github_repo

mu-majid/Node.JS-Self-Study-Projects

discovered 2026-09-17

PolinRider-infected GitHub repository. Delivery via a malicious .vscode/tasks.json that stages the fa-solid-400.woff2 payload dropper. DPRK-linked per the detection source (medium confidence; new attribution not previously on the campaign). Campaign code signatures rmcej%otb% / Cot%3t=shtP, XOR keys, and Tron wallet addresses appear in this delivery pattern. User-supplied link; no commit timestamp recorded.

Campaigns