PolinRider malware attributed to DPRK's Lazarus group was detected in two open pull requests (#7716, #10321) targeting PostCSS and Tailwind configuration files. The malware uses obfuscated JavaScript code appended to legitimate config content and executes via eval with C2 communication over Ethereum JSON-RPC endpoints. Both PRs should not be merged without removing the malicious payload.
A malicious npm campaign distributing the 'indexed-btree' package and nine related libraries bypasses GitHub's 2026 supply chain defenses by hiding malware in runtime code execution rather than installation scripts. The malware collects system information and uses Ethereum smart contracts for command-and-control, with the campaign achieving millions of downloads across affected packages.