BindsNET disclosed that clones of its repository executed malicious code between August 29 and September 2, 2026. Every branch, including master, contained a concealed Visual Studio Code task that could automatically run attacker-controlled code through VS Code task behavior when the repository was opened or its tasks were triggered.
The incident is tracked as GitHub Security Advisory GHSA-6f2q-w3r8-xxhj and has been associated publicly with VS Code and PolinRider. The available disclosure does not identify the attacker, payload, affected users, initial access method, or remediation; organizations that cloned BindsNET during the exposure window should treat affected workstations and development credentials as potentially compromised and investigate repository task configuration and execution activity.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Between August 29 and September 2, 2026, every branch of the BindsNET repository, including master, contained a hidden Visual Studio Code task designed to automatically execute attacker-controlled code when a repository clone was opened or triggered through VS Code task behavior.
BindsNET disclosed that malicious code executed on cloned repositories during the August 29–September 2 incident. The disclosure was documented as GitHub Security Advisory GHSA-6f2q-w3r8-xxhj.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.