BindsNET
#BindsNET • 2026-08
Between August 29 and September 2, 2026, attackers using a compromised collaborator account force-pushed a forged merge commit across 20 BindsNET GitHub branches, and a routine Dependabot merge carried the malicious files into the master branch. Opening an affected clone in VS Code, Cursor, or VSCodium with Node.js available triggered a hidden folder-open task that ran obfuscated JavaScript and fetched an unknown second-stage payload, requiring exposed developers to treat their systems as compromised and rotate credentials. PyPI releases and BindsNET source files were unaffected; maintainers removed the 21 injected files, restored the overwritten branches, and strengthened repository protections.
-
2
Related Reports
-
0
Affected Countries
-
1
Months Since