2026-10-11 16:38 UTC

Security reporter 6mile alleges two open shadcn/ui pull requests contain executable PolinRider payloads appended to build configurations, creating a maintainer-compromise risk before merge as well as a potential downstream supply-chain threat.

state: seedheat: highuncertainty: mediumconvergesscott: highsupply-chain-security malicious-pull-requests developer-security6mileshadcn-ui
Surfaced 2026-09-21T11:21:58Z β€” Reports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro β€” Security reporter 6mile alleges two open shadcn/ui pull requests contain executable PolinRider payloads appended to build configurations, creating a maintainer-compromise risk before merge as well as a potential downstream supply-chain threat.

What is this?

A GitHub security issue (#11971) in the shadcn/ui repository documents two open pull requests (#7716, #10321) containing PolinRider malware payloads appended to PostCSS/Tailwind config files β€” hidden after legitimate content with whitespace padding to evade code review. The campaign is attributed to a North Korean threat actor (DPRK) targeting developer supply chains across npm, Packagist, Go modules, and Chrome extensions. The shadcn-ui maintainers are advised not to merge the PRs as-is, to strip the malicious config changes, and to contact the contributor accounts (shakin-shahria, stefann01) for potential account compromise. Multiple security firms (Sonatype, Wiz, Socket, Rescana) have independently reported on the broader PolinRider campaign.

Why it matters to Scott

This case is a live, high-profile instance of the exact transitive supply-chain compromise Scott's 'Breach Doesn't Compose' framework argues is inevitable when systems rely on review-time trust instead of architectural containment. The PolinRider payloads evade code review via whitespace padding β€” demonstrating the 'guardrail illusion' and 'compliance cosplay' failure modes β€” while the shadcn/ui component library's position in the npm ecosystem makes this a canonical 'breach composes' event: one malicious PR in a widely reused UI primitive cascades to downstream dependents. This independently validates Scott's thesis that containment must be structural (capability-scope separation, sandboxed execution, verification boundaries, execution attestation) and that governance must live in the execution path (Decision Authority Infrastructure, Two Leashes), not in review-time promises.
ip:framework.breach-doesnt-composeip:source.breach-doesnt-compose-ebookip:framework.architecture-not-vibesip:framework.hidden-gates-frameworkip:source.hidden-gates-ebookip:source.security-reviewer-method-ebookip:concept.architectural-containmentip:concept.runtime-containmentip:concept.provenanceip:concept.verification-boundaryip:concept.sandboxed-executionip:concept.execution-attestationip:concept.governance-as-architectureip:concept.padded-cell-agent-architectureip:concept.validation-gated-llm-extractionip:concept.verbatim-source-evidence-anchoringip:concept.ephemeral-source-ai-reviewip:framework.agent-provenance-stackip:source.agent-provenance-stackip:framework.two-leashesip:source.two-leashes-ground-the-cognition-constrain-the-execution-ebookip:framework.decision-authority-infrastructureip:source.governance-as-codeip:source.compliance-cosplayip:source.the-governance-stackradar:concept.software-supply-chainradar:concept.supply-chain-securityradar:concept.npm-supply-chainradar:concept.developer-supply-chainradar:concept.code-reviewradar:concept.ai-code-reviewradar:concept.credential-theftradar:concept.credential-securityradar:concept.credential-isolationradar:concept.ai-assisted-securityradar:concept.security-agentsradar:concept.dependency-securityradar:concept.vulnerability-researchradar:git-yard-backdoor-detectionradar:subql-common-npm-compromiseradar:ghostaction-typosquatting-supply-chainradar:arrayref-crates-supply-chain-compromiseradar:git-postcheckout-credential-theftradar:keycloak-reset-bypass-cve-2026-18963radar:keycloak-reset-credentials-takeoverradar:omarchy-any-process-root-escalationradar:mikrotrick-unauthenticated-ssh-takeoverradar:sourcehut-build-log-xssradar:claude-subscriber-token-theftradar:github-copilot-review-resolutionradar:harnesseval-code-review-gainsradar:copilot-review-skills-mcp-validationradar:openai-codex-auto-reviewradar:nitpicker-self-hosted-pr-reviewradar:proval-local-code-reviewradar:rudder-spec-derived-agent-testsradar:aisle-six-curl-cvesradar:google-agentic-source-review-securityradar:palo-alto-continuous-ai-defenseradar:cyberstrike-offensive-security-harnessradar:sentinel-scan-agent-red-team-auditradar:vibeguard-ai-code-security-linterradar:safer-dependencies-claude-code-auditingradar:augur-hidden-content-scannerradar:acs-local-skill-risk-catalogradar:skillpreflight-agent-skill-scoringradar:favz-github-agent-config-censusradar:mcp-unversioned-tool-drift
queries asked of Scott's wikis
  • supply-chain security malicious PR detection
  • code review automation hidden payload detection
  • developer tooling compromise account takeover
  • open source dependency risk monitoring
  • AI-assisted security review malicious code

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 530h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-21 10:14⭐ origin directly observedSecurity: PolinRider malware detected in two open PRs (#7716, #10321)
fr0th on hacker news
β€”
09-19 14:00first on github (echo) Β· published Β· +-44.2hReports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro
6mile
β€”
09-21 10:14amplified on hacker news πŸ‘‘hn.story.49785327
fr0th
peak 1 Β· 0 comments Β· 106% of case engagement
09-21 10:20our radar first saw it Β· +0.1hdiscovery anchor: hn.story.49785327β€”
pace: p9 vs 1032 stories at the 336h mark (now 530h old) β€” behind addom-local-coding-harness (0.5x)

Evidence (2) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Security: PolinRider malware detected in two open PRs (#7716, #10321)
Retrieved article excerpt

Open article Β· Retrieved 2026-09-21T10:22:33.066959+00:00

[shadcn-ui](https://github.com/shadcn-ui) 
/
**[ui](https://github.com/shadcn-ui/ui)**
Public

- ### Uh oh!

  There was an error while loading. [Please reload this page](https://github.com/shadcn-ui/ui/issues/11971).
- [Notifications](https://github.com/login?return_to=%2Fshadcn-ui%2Fui) You must be signed in to change notification settings
- [Fork
  10.9k](https://github.com/login?return_to=%2Fshadcn-ui%2Fui)
- [Star
   124k](https://github.com/login?return_to=%2Fshadcn-ui%2Fui)

# Security: PolinRider malware detected in two open PRs (#7716, #10321)Β #11971

New issue

Copy link

New issue

Copy link

Open

Open

[Security: PolinRider malware detected in two open PRs (#7716, #10321)](https://github.com/shadcn-ui/ui/issues/11971#top)#11971

Copy link

## Description

[@6mile](https://github.com/6mile)

[6mile](https://github.com/6mile)

opened [on Sep 20, 2026](https://github.com/shadcn-ui/ui/issues/11971#issue-5517382099)

Issue body actions

## Security Alert

PolinRider malware (DPRK-attributed, Lazarus/Contagious Interview cluster) has been detected in **two independent open pull requests** against this repository.

### Affected PRs

**PR [#7716](https://github.com/shadcn-ui/ui/pull/7716)** ("[bug]: Calendar year, month dropdown height issue [#7680](https://github.com/shadcn-ui/ui/issues/7680)") β€” submitted from `shakin-shahria/ui`

- Touches `apps/v4/postcss.config.mjs`, `templates/monorepo-next/apps/web/postcss.config.mjs`, `templates/monorepo-next/packages/ui/postcss.config.mjs`, plus several `tailwind.config.js` test fixtures
- Payload verified present in the diff (obfuscated code appended after the legitimate config content)

**PR [#10321](https://github.com/shadcn-ui/ui/pull/10321)** ("feat: Image upload component") β€” submitted from `stefann01/ui`

- Touches `apps/v4/postcss.config.mjs` and multiple `postcss.config.mjs`/`tailwind.config.js` files across templates and test fixtures
- Payload verified present in the diff

### Indicators

- Marker: `global.i="A#-..."` (e.g. `A9-3443-2`) β€” a payload variant using javascript-obfuscator.io-style hex/opcode packing, internally remapped to a `global['_V']` reference
- Execution via `eval`/`spawn`, C2 over rotating public Ethereum JSON-RPC endpoints
- Appended after otherwise-legitimate config content, easy to miss in a large diff

### Remediation

1. Do not merge PR [[bug]: Calendar year, month dropdown height issue #7680Β #7716](https://github.com/shadcn-ui/ui/pull/7716) or [feat: Image upload componentΒ #10321](https://github.com/shadcn-ui/ui/pull/10321) as-is
2. Strip the postcss/tailwind config changes from both PRs before considering any legitimate portions
3. Reach out to both account owners (`shakin-shahria`, `stefann01`) to check for compromise β€” this is consistent with account takeover, not necessarily malicious intent from the original account owner

### References

- <https://opensourcemalware.com>
- Reported via automated threat hunting

Reactions are currently unavailable

## Activity

[Sign up for free](https://github.com/signup?return_to=https://github.com/shadcn-ui/ui/issues/11971) **to join this conversation on GitHub.** Already have an account? [Sign in to comment](https://github.com/login?return_to=https://github.com/shadcn-ui/ui/issues/11971)

## Metadata

## Metadata

### Assignees

No one assigned

### Labels

No labels

No labels

### Type

No type

### Projects

No projects

### Milestone

No milestone

### Relationships

None yet

### Development

No branches or pull requests

## Issue actions

- Open in GitHub Copilot app
fr0th10
🟧 echo.githubReports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro6mileβ€”β€”

Interpretation history

Decision trace