Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-27 · updated: 2026-09-27 · tags: [incident, global] · confidence: high · severity: low · affected_sectors: [global] · au_impact: true

OpenSourceMalware has documented the DPRK-linked PolinRider campaign running what its analysts read as deliberate A/B testing of its own detection-evasion technique. The mechanism is unchanged — a .vscode/tasks.json file that runs a payload stored as a Font Awesome .woff2 file when the folder opens — but the payload filename has moved from fa-solid-400.woff2 to fa-solid-500.woff2 and then to fa-solid-900.woff2, a genuine Font Awesome filename, in a folder that now holds only standard font names, and at 37.5 KB against the original 5.5 KB. The case study is a three-repository development agency infected since 29 January, when a contributor account force-pushed a VS Code task piping a script from 260120.vercel[.]app into the shell: GitHub's own activity log records 853 force-pushes across the three repos and 19 accounts pushing over eight months, with the malware rewriting commits on infected machines and re-infecting teammates who open the repos. The victim-side signal is a recurring .gitignore block (config.bat, temp_auto_push.bat, temp_interactive_push.bat, branch_structure.json) that hides the auto-push working files from git status — its presence means a contributor's machine is infected, not merely that a repository is dirty. Developers in the organisation removed the malware at least three times; it returned each time from another infected machine. Indicators include the C2 paths :443/0x/cls and :443/0x/ls, an Ethereum dead-drop wallet and the SHA-256 1a21bad1df69b51efebfd2fae849ac27722b0dfac7b1cb459cf81d38b36f9705.

Attribute Detail
Sector Global (Macro)
Date 2026-09-27
Source OpenSourceMalware
Reliability Tier 2