OpenSourceMalware has documented the DPRK-linked PolinRider campaign running what its analysts read as deliberate A/B testing of its own detection-evasion technique. The mechanism is unchanged — a .vscode/tasks.json file that runs a payload stored as a Font Awesome .woff2 file when the folder opens — but the payload filename has moved from fa-solid-400.woff2 to fa-solid-500.woff2 and then to fa-solid-900.woff2, a genuine Font Awesome filename, in a folder that now holds only standard font names, and at 37.5 KB against the original 5.5 KB. The case study is a three-repository development agency infected since 29 January, when a contributor account force-pushed a VS Code task piping a script from 260120.vercel[.]app into the shell: GitHub's own activity log records 853 force-pushes across the three repos and 19 accounts pushing over eight months, with the malware rewriting commits on infected machines and re-infecting teammates who open the repos. The victim-side signal is a recurring .gitignore block (config.bat, temp_auto_push.bat, temp_interactive_push.bat, branch_structure.json) that hides the auto-push working files from git status — its presence means a contributor's machine is infected, not merely that a repository is dirty. Developers in the organisation removed the malware at least three times; it returned each time from another infected machine. Indicators include the C2 paths :443/0x/cls and :443/0x/ls, an Ethereum dead-drop wallet and the SHA-256 1a21bad1df69b51efebfd2fae849ac27722b0dfac7b1cb459cf81d38b36f9705.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-27 |
| Source | OpenSourceMalware |
| Reliability | Tier 2 |