Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Initially it weaponized credentials stolen by TasksJacker, and we consider it a parallel or sub-campaign to Contagious Interview.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware still... spreads through the victims’ own GitHub accounts... Review your GitHub account for unauthorized pushes — the campaign spreads by pushing the payload back out through victim accounts.
The technique is .vscode/tasks.json with "runOn": "folderOpen" ... For trusted workspaces, that happens silently, before any code review ... Drop a tasks.json like that into a repository, get a developer to open the repository in VS Code, and you have remote code execution on their machine.
the malware still... spreads through the victims’ own GitHub accounts... Review your GitHub account for unauthorized pushes — the campaign spreads by pushing the payload back out through victim accounts.
the malware still... spreads through the victims’ own GitHub accounts... Review your GitHub account for unauthorized pushes — the campaign spreads by pushing the payload back out through victim accounts.
This heavily obfuscated JavaScript: Establishes communication with blockchain APIs ... Fetches encrypted payloads from Binance Smart Chain transactions XOR decrypts payloads with static keys
The threat actors didn't just inject malicious files. They rewrote git history to make their changes appear legitimate.
Stage 3A: Information Stealer (Immediate) ... SSH keys ( ~/.ssh/ ) AWS credentials ( ~/.aws/ )
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool referenced as connected to the PolinRider reporting, but not the main subject of this specific reference.
Malware associated with stolen credentials and .vscode/tasks.json payloads that appears operationally linked to PolinRider; some repositories contained both PolinRider config injections and a TasksJacker payload, indicating campaign overlap or merger.
"How malware abuses npm lifecycle scripts and VS Code tasks" published by OSM. #Axios, #NPM, #TasksJacker, #DPRK, #CTI
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.