PolinRider is A/B Testing its Way Past Your Detections

2026-09-26 • Open Source Malware •

https://opensourcemalware.com/blog/polinrider-is-a-b-testing-its-way-past-your-detections

Thumbnail for PolinRider is A/B Testing its Way Past Your Detections

PolinRider, a DPRK-linked cluster associated with Contagious Interview activity, is testing multiple infection variants across compromised GitHub repositories rather than replacing each build in a linear sequence. An eight-month Binary-Mindz infection involved 853 force-pushes, malicious VS Code tasks, fake `.woff2` font files, executable ESLint and Prisma configurations, and repeated restoration of malware after developer cleanups. The 500 variant uses an Ethereum-based NullReceiver dead drop and reports its build marker to the C2 server, while the more heavily obfuscated 900 variant hides under a legitimate Font Awesome filename. Detection should focus on file contents, automatic folder-open tasks, repository-wide force-push patterns, executable configuration files, and infected contributor machines rather than fixed filenames or commit history alone.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fbf0e36dd7eb1e70fc4868a8d0d0cd8… 2026-09-26 2026-09-26
HASH 91e334655d31f84963e6b9369d41698… 2026-09-26 2026-09-26
HASH 1a21bad1df69b51efebfd2fae849ac2… 2026-09-26 2026-09-26
URL https://260120.vercel.app/setti… 2026-09-26 2026-09-26
URL https://260120.vercel.app/setti… 2026-09-26 2026-09-26
URL https://github.com/GulamRosul/C… 2026-09-26 2026-09-26
URL https://github.com/Binary-Mindz… 2026-09-26 2026-09-26
URL https://github.com/Binary-Mindz… 2026-09-26 2026-09-26
URL https://github.com/Binary-Mindz… 2026-09-26 2026-09-26
WALLET 0xa322e5f3d311d3080e6f0121063e9… 2026-08-02 2026-09-26

Related Actors

Related Reports

« Back