Obfuscated code suddenly appearing in next.config.js / postcss.config.js without direct file changes #188732
Replies: 22 comments 26 replies
|
Hi @robellorin, The same thing is happening to me and my team. We haven’t been able to find the cause, but it appears to be using a force push to rewrite the commit history. If you find any solution, please let us know. |
|
Seems to have affected few of my repos, pls let us know if you find any solution. |
|
Based on analysis of this attack, here is a likely attack chain that explains what you're seeing: Probable attack chain:
This explains two things people find confusing:
Specific IOCs to search for:
Recommended cleanup:
The blockchain-based C2 (as @semitha-dev noted) means the actual payload was never on disk — antivirus will always report clean. |
|
This also affects I found this article which explains what happens a bit more. |
|
Here’s an online tool that helps identify infected repositories and clean malicious code Here Thought this might be useful for the community. |
|
This also affects |
|
This also happened to me. Here is what I’ve done so far. First, you can run this command to check whether the malware process is currently running on your machine: ps aux | grep -Ei "global\['_V'\]|A10-010|A10-2340|global\['r' \]=require|_t_t|166\.88\.54\.158|198\.105\.127\.210|23\.27\.202\.27" | grep -v grepIf it returns a From what I’ve seen, the malware usually injects itself into config files. But in my case, it also created fake font files under the I thought I had removed it everywhere and was safe, but yesterday the malware pushed commits to all repositories that my GitHub account had access to. Very annoying. And there is no evidence commit actually was edited. Author is same, dates are same. I only do see updated x hrs ago mark on github and when i do pull i do see all of my branches was force pushed. So far, I have revoked my GitHub HTTPS access, recreated my SSH key, revoked OAuth application access, removed old sessions/tokens, and now I’m cleaning the affected repositories. Also, block the known malicious IPs on your machine/firewall if possible: 166.88.54.158
198.105.127.210
23.27.202.27
154.91.0.103
136.0.9.8
166.88.4.2
23.27.120.142
202.155.8.173
166.88.134.82
188.43.33.249I also realized it adds following code into my main.ts on nest.js project AUTH_API_KEY=https:// auth-confirm-l emon-alpha . vercel . app/api (Dont click) Which is a vercel app it was added base64 encoded. |
|
Any idea what the main source of this virus is? Most projects I am working on were created from scratch, then how did my laptop get infected? Also, what is this virus trying to accomplish? What are they gaining from all of this? |
|
This happened to me as well. I was using cursor and I was just used: npm i --> npm run dev And it affected eslint.config.mjs and then also put a config.bat in my .gitignore. WIndow defender quarantined the file and also gave: Trojan:JS/PolinRider.DB!MTB as a detection for the file. EDIT: We really have to pin down which specific library is causing this. because it has happened to vue, next and every other platform. |
|
Hi everyone, this threat actor and campaign are named PolinRider, and I have written about it extensively here: https://opensourcemalware.com/blog?q=polinrider I also maintain a GitHub repo with a TON of data about this malware and threat actor. You can see it here: https://github.com/OpenSourceMalware/PolinRider PolinRider is a North Korean operation and the DPRK is using access on infected machines to spread the malware by pushing the payloads into existing repos with forced git commits. North Korean actors use Git history rewriting and force-pushes combined with anti-dated timestamps to conceal software supply chain attacks. By manipulating commit metadata and force-pushing changes, they make malicious code injections appear old, benign, and seamlessly blended into legitimate repository histories. If you look at the git history in GitHub you won't see any changes, but if you inspect the older commit you will see the new malicious payload. Thousands of GitHub users are compromised!@semitha-dev 's suggestions are correct and great at determining if you have been compromised and how to mitigate that compromise. BE AWARE - Most of the PolinRider infections use VSCode tasks files for the initial infection.VSCode has a function built into it that will run tasks held in a tasks.json file. These tasks will run the PolinRider malware on your machine. The payloads are always JavaScript, but unfortunately, that works in any language repository because the payload run by the tasks.json installs Node, then runs the JS payload. We have seen PolinRider malware in PHP, Go, Rust, Ruby, Typescript, and other languages. The bad guys will write into many different files. Some of the ones I've seen are:
But they are probably appending payloads to any type of JavaScript file they can find. |
|
@semitha-dev's work in this thread is genuinely awesome. I do threat research related to this campaign, and hear from a ton of people with questions about how they got infected in the first place, why it's so persistent, and mitigation. I wrote this guide to pull it all together: |
|
Hello folks, After nearly two months of inactivity, the malware has started pushing changes to all repositories and branches again. While deobfuscating the malware, I found the following code: I also found that the malware is using the following Ethereum address: https://etherscan.io/address/0xa322e5f3d311d3080e6f0121063e9adc2490ef1a It appears to be using Ethereum transactions as a dynamic C2 discovery mechanism: the destination address of the latest transaction is decoded into IP addresses, which are then used to download and execute additional payloads. |
IOCs from a machine I just cleaned (macOS, Next.js project)Adding concrete indicators in case they help others confirm the same strain. Entry vector: a project ZIP handed to me as a starter — the poisoned Indicators of Compromise
Persistence people may miss: it doesn't just live in config files — it also patched npm itself. Quick self-checks # 1. any oversized config file (normal is < 1 KB)
find ~ -maxdepth 4 \( -name "postcss.config.*" -o -name "next.config.*" -o -name "tailwind.config.*" \) \
-not -path "*/node_modules/*" -size +2k 2>/dev/null
# 2. is npm patched? (clean cli.js is ~216 bytes)
wc -c "$(dirname "$(which npm)")/../lib/node_modules/npm/lib/cli.js"
# 3. hidden detached processes
ps -eo pid,etime,command | grep -a "node -e global" | grep -v grep
Cleanup that worked: kill the detached node -e procs → strip the payload from every infected config → reinstall the Node version (don't hand-fix npm with npm) → reboot → re-scan. Then rotate everything the machine could read (wallets, browser creds, SSH keys, .env, GitHub/npm tokens) from a clean machine, and check GitHub for unfamiliar commits/force-pushes. Given a system binary (npm) was modified, a full reimage is the safe call.
IOCs vary between samples — the C2 IP / wallets may differ for you; the behavioural signs (whitespace-hidden payload, oversized configs, patched npm, reboot-surviving node -e procs) are the reliable tells. |
|
I got hit by what looks like the same campaign. Still no idea how I originally got infected. One additional finding: it modified npm itself:
A large obfuscated payload was appended to the normal npm code. Some additional signatures I found:
I also found the payload in Might be worth checking the npm installation itself, not just project files |
|
I confirmed a related macOS infection, with one important additional finding: cleaning only Findings
A clean npm Cleanup performed
Prevention
The main takeaway: also inspect npm’s own |
|
@echo off I found this script in bat file |
|
{ i also found this in backend repo as well |
|
I would treat this as a possible supply-chain or build-environment incident until the provenance is explained. A few checks help separate a Git-history problem from code generated or modified outside the commit:
For prevention, make generated files reproducible and review their diffs, pin and verify dependencies/actions, restrict workflow token permissions, run builds on disposable runners, and add a secret scan plus a malware/static-analysis gate for configuration files. If the payload is confirmed malicious, report it through the affected package/forge security process and publish a minimal indicator timeline without sharing live secrets. The most important evidence is the first commit where the blob exists, the commit that introduced the blob into each tree, and the process that wrote it into any workspace or artifact. “The file changed later” is not enough to establish that Git caused the change. |
|
I'm investigating a similar incident on macOS and could use help with the remaining persistence checks and identifying how the initial GitHub writes happened These are the findings we could confirm
I still don't know how they got access, the force-pushes happened before the malware activity we caught on my Mac I stopped the malicious processes we found, saved the infected files and replaced npm with a clean official copy, also checked Node against the official release The branches are restored and I revoked several OAuth grants, but I still don't know if we missed anything on the Mac or which other credentials might have been exposed The hooks I had to prevent this crap didn't catch it in time, the dev server I was using to work was already running and loaded the infected config as soon as Git brought it in By the time the config was cleaned, the malware was already running and npm was infected too Has anyone investigated this I'm particularly looking for a maintained, read-only scanner covering developer-tool persistence, and advice on which GitHub audit fields or Support requests can distinguish an OAuth/API write from an SSH push when the event only identifies the account Also, are there specific persistence locations beyond npm, editor application files, startup files and LaunchAgents that you found in this variant? |
|
Two things I haven't seen covered in this thread yet, in case they help someone: 1. Check every branch, not just the one you have checked out. The payload is often force-pushed to branches you never look at, and the GitHub copy can differ from your local one: git fetch --all
for ref in $(git for-each-ref --format='%(refname)' refs/heads refs/remotes); do
git grep -l -F -e "global['!']=" -e "global['_V']=" -e '_$_1e42' "$ref" -- '*config*.js' '*config*.mjs' '*config*.cjs' '*config*.ts'
done2. Forged merge commits. Some variants push a copy of a real "Merge pull request #N" commit with the same author, date and message. A merge made with GitHub's button has the committer git log --all --merges --format='%h %G? committer: %cn <%ce> %cd %s' --date=iso | grep 'Merge pull request'Also check whether Disclosure: I maintain a free, MIT-licensed, read-only bash script that runs these checks across all branches (no npm/node, no network): https://github.com/itskill-jp/vite-config-malware-check |
|
Hi everyone, maybe this is what you are looking for, I'm not entirely sure, but what I posted is the absolute reality. I might explain it in private. UNREGISTRABLE BUS-DODGING ATTACK |

Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Select Topic Area
General
Body
Hi everyone,
I recently noticed something strange in a few private repositories I worked on. Around November 15, heavily obfuscated JavaScript code suddenly appeared in configuration files like next.config.js and postcss.config.js.
The unusual part is that the commits where these files appeared do not clearly show intentional changes to those files. In some cases, the code shows up in a later PR even though the file wasn’t modified in the previous commit. This also happened across multiple repositories and even under commits from different developers.
The injected code looks like an obfuscated loader that decodes and executes hidden payloads, which made me concerned it might be malicious or the result of some automated injection (possibly from a dependency or build process).
Has anyone seen something similar before or knows what might cause this behavior?
[Links edited by staff]
Thanks.
All reactions