fix(security): remove hidden VS Code folder-open loader task and fake font - #1
polylane[bot] wants to merge 2 commits into
Conversation
Co-authored-by: polylane[bot] <277585245+polylane[bot]@users.noreply.github.com>
There was a problem hiding this comment.
Thank you for submitting your first pull request! 🎉 Your effort and contribution are greatly appreciated. Our maintainers will review your changes soon. In the meantime, please ensure your submission aligns with our Contribution Guidelines Let me know if you have any questions. Welcome aboard! 🙌 | Omar Santos @santosomar
|
Warning Polylane could not verify the production impact of this pull request. Checked h4cker against the whole account: zero deploy edges, no Vercel project builds it, and 54 deploys/72h come from other projects; org code search finds no consumer of the deleted asset. Vercel observability returned nothing (no Observability Plus). Also considered · 4 refuted
Analysed against 1 cloud account and 1 repository
Polylane could not find the cloud resources this repository manages, so this review looked at the entire cloud account. Connect this repository to its resources and the next review will focus on exactly what this code deploys to. Polylane analysed Rate this review: 👍 helpful · 👎 not helpful · 😕 confusing |
f3819b2 to
3821b56
Compare
|
This pull request is waiting on a decision: merge it if the change is still wanted, or close it if the fix is no longer needed. Either one settles it. It was opened on 2026-09-19 and has had no new activity for a week. If nothing happens on it within a week, Polylane closes it and keeps the branch, so reopening it brings the change back exactly as it stands. @phoenixdahdev, the change touches what you own, so the review is with you. |
|
This pull request is closing without a merge, and nothing is lost: the branch It was opened on 2026-09-19, Polylane reminded the maintainers about it on 2026-09-27, and nothing has happened on it since. @phoenixdahdev, you were asked to review this pull request; reopening it puts it back on your list. |
Fixes: Hidden VS Code folderOpen task re-infects 18 phoenixdahdev repos with Ethereum-C2 loader
Opening this repository in VS Code silently ran a script that had been committed to look like a web font, started a remote payload on the developer's machine, and re-infected the owner's other projects every time a folder was opened. This change removes the hidden auto-run task, disables the setting that let it run without asking, and deletes the fake font.
What caused this
Affected:
int_0b2300ad4001ia0oribh5vgeWhy this fix
This repository is one of five that carry byte-identical copies of a planted bundle:
.vscode/tasks.json(git blob1a828db9, 799 B) whose only task iseslint-checkwithrunOn: folderOpen, and.vscode/settings.json(blob934d5554, 786 B) withtask.allowAutomaticTasks: true, which is what let that task run without a prompt. The task runsnode ./public/fonts/fa-solid-500.woff2. That file is 7,592 bytes of ASCII source that begins with the campaign markerA8-4893-2and reaches out for a second stage, while the genuine Font Awesome binaries stored beside it are 13 KB to 800 KB and are real font containers.Identical bytes appear in repositories whose other commits are authored by three different people — h4cker's upstream is a public security reference maintained by another author, and the SwiftUI and Expo projects are other people's as well — so this is not a per-project developer preference: one injector planted the same three files everywhere. Emptying the task list stops the schedule, and flipping the setting to
falseremoves the silent-run condition, so a future planted task cannot run unprompted on a folder open. Deleting the asset is what makes the loader unreachable.The evidence that nothing else depends on these files is a repository-wide search:
git grep fa-solid-500returns nothing after the change, so no font-face rule, stylesheet, or application import referenced the asset, and both edited JSON files parse. The consequence for a reader is that the folder-open execution path in this repository is gone.Remaining work is outside this diff: the loader blob is still reachable at older commits, so a clone of a historical commit can still run it, and purging that needs a history rewrite and coordinated re-clones, which is the owner's call. Credential rotation for anything the loader could reach from a developer machine is also the owner's.
3 files changed (+2/-23)
.vscode/settings.json: modified, +1/-1.vscode/tasks.json: modified, +1/-21public/fonts/fa-solid-500.woff2: removed, +0/-1Generated by Polylane. You can ask follow-ups by mentioning @polylane in a comment.