PolinRider malware attributed to DPRK's Lazarus group was detected in two open pull requests (#7716, #10321) targeting PostCSS and Tailwind configuration files. The malware uses obfuscated JavaScript code appended to legitimate config content and executes via eval with C2 communication over Ethereum JSON-RPC endpoints. Both PRs should not be merged without removing the malicious payload.