Their GitHub Repo Was Compromised. The Trail Led to North Korea.

2026-09-27 • tarunrd77 •

https://medium.com/@tarunrd77/their-github-repo-was-compromised-the-trail-led-to-north-korea-6d332abbdedf

Thumbnail for Their GitHub Repo Was Compromised. The Trail Led to North Korea.

An investigation into a compromised Web3 and fintech GitHub repository found a malicious VS Code workspace task that invoked Node.js on an embedded WOFF2 file carrying an obfuscated JavaScript loader. The loader used an Ethereum wallet as a dead-drop resolver for rotating C2 IPs and retrieved second-stage payloads from the resulting infrastructure. The author linked the infrastructure and code overlaps to DPRK-linked PolinRider and NullReceiver activity, while noting that the initial repository entry vector was not established.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://166.88.134.62/0x/ls 2026-09-27 2026-09-27
URL http://166.88.134.62/0x/js 2026-09-27 2026-09-27
URL http://166.88.134.62/0x/cls 2026-09-27 2026-09-27
HASH f752dcf2a1d86d4a978cb7a5ddab21e1 2026-09-27 2026-09-27
IPv4 166.88.134.75 2026-09-21 2026-09-27
WALLET 0xa322E5f3D311D3080e6f0121063e9… 2026-09-17 2026-09-27
IPv4 193.247.144.38 2026-09-02 2026-09-27
IPv4 23.27.13.135 2026-09-02 2026-09-27
IPv4 166.88.73.46 2026-09-02 2026-09-27
IPv4 166.88.134.62 2026-07-28 2026-09-27

Related Actors

Related Reports

« Back