A malicious pull request against the Egonex-AI/Understand-Anything GitHub repository inserted an obfuscated payload into homepage/astro.config.mjs, abusing Astro’s automatic execution of that file during development, build, and preview workflows. SafeDep reported that the PR, presented as a harmless dashboard bug fix, actually changed only .gitignore and astro.config.mjs, with the malicious code concealed behind extensive horizontal whitespace to reduce visibility in GitHub’s diff view. The payload restored require in an ES module context, contacted one of three hardcoded command-and-control servers, exfiltrated a campaign marker, decrypted and executed a downloaded bot client, and fetched a second-stage command through a Tron-to-Aptos-to-BSC blockchain relay.
The attack was disclosed publicly in issue #432 and attributed by SafeDep to the DPRK-linked PolinRider campaign based on matching cryptographic and infrastructure fingerprints, a link later amplified in threat-intelligence social media reporting. SafeDep said the intrusion fits its malicious pull request threat model, in which attackers compromise upstream repositories through contributor PRs rather than poisoned dependencies, and warned that any environment that ran Astro commands from the affected branch should be treated as compromised. Recommended response actions include rotating credentials, reviewing network logs, and hunting for suspicious createRequire, outbound network access, or eval behavior inside build configuration files.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
A Bluesky post by the account lazarusholic shared the SafeDep publication and associated it with the hashtags #PolinRider, #DPRK, and #CTI. The post served as social amplification of the reported attribution and attack details.
SafeDep published a report detailing the astro.config.mjs supply chain attack, including blockchain-relayed C2 behavior and build-time payload execution. The report attributes the activity to the DPRK-linked PolinRider campaign based on matching cryptographic and infrastructure fingerprints.
The attack was publicly disclosed in issue #432. The disclosure identified the PR-based supply chain compromise involving astro.config.mjs and its build-time payload behavior.
A malicious pull request, #206, was submitted to the Egonex-AI/Understand-Anything GitHub repository. It inserted an obfuscated payload into homepage/astro.config.mjs and modified .gitignore while masquerading as a benign dashboard bug fix.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.