PolinRider malware attributed to DPRK's Lazarus group was detected in two open pull requests (#7716, #10321) targeting PostCSS and Tailwind configuration files. The malware uses obfuscated JavaScript code appended to legitimate config content and executes via eval with C2 communication over Ethereum JSON-RPC endpoints. Both PRs should not be merged without removing the malicious payload.
Prominent Rust developers and crate owners are being targeted in an ongoing campaign using social engineering via fake video calls to compromise devices and accounts for publishing malware. Attackers create legitimate-seeming company profiles and LinkedIn presences to gain trust. This attack style is attributed to DPRK and has previously compromised Rust developers in June and the arrayref crate last month.