Cloning a Repo Is Code Execution [Part 2] — Attacking the Trust Instead of the Code

In [Part 1] I pulled apart two compromises of one codebase by hand – a fake font that ran on folder-open, and a babel.config.js that turned every build into a remote-access trojan. Both, it turns out, belong to a publicly-documented campaign: public reporting attributes that family to a DPRK-linked actor tracked as PolinRider (also Void Dokkaebi). I didn’t prove that myself – my analysis was static – but the shared Tron dead-drop, the commit-spoofing tool, and the 166.88.54.158 C2 line up with what Trend Micro and others have published.

[Read More]