Security reporter 6mile alleges two open shadcn/ui pull requests contain executable PolinRider payloads appended to build configurations, creating a maintainer-compromise risk before merge as well as a potential downstream supply-chain threat.
state: seedheat: highuncertainty: mediumconvergesscott: highsupply-chain-security malicious-pull-requests developer-security6mileshadcn-ui
Surfaced 2026-09-21T11:21:58Z β Reports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro β Security reporter 6mile alleges two open shadcn/ui pull requests contain executable PolinRider payloads appended to build configurations, creating a maintainer-compromise risk before merge as well as a potential downstream supply-chain threat.
What is this?
A GitHub security issue (#11971) in the shadcn/ui repository documents two open pull requests (#7716, #10321) containing PolinRider malware payloads appended to PostCSS/Tailwind config files β hidden after legitimate content with whitespace padding to evade code review. The campaign is attributed to a North Korean threat actor (DPRK) targeting developer supply chains across npm, Packagist, Go modules, and Chrome extensions. The shadcn-ui maintainers are advised not to merge the PRs as-is, to strip the malicious config changes, and to contact the contributor accounts (shakin-shahria, stefann01) for potential account compromise. Multiple security firms (Sonatype, Wiz, Socket, Rescana) have independently reported on the broader PolinRider campaign.
Why it matters to Scott
This case is a live, high-profile instance of the exact transitive supply-chain compromise Scott's 'Breach Doesn't Compose' framework argues is inevitable when systems rely on review-time trust instead of architectural containment. The PolinRider payloads evade code review via whitespace padding β demonstrating the 'guardrail illusion' and 'compliance cosplay' failure modes β while the shadcn/ui component library's position in the npm ecosystem makes this a canonical 'breach composes' event: one malicious PR in a widely reused UI primitive cascades to downstream dependents. This independently validates Scott's thesis that containment must be structural (capability-scope separation, sandboxed execution, verification boundaries, execution attestation) and that governance must live in the execution path (Decision Authority Infrastructure, Two Leashes), not in review-time promises.
ip:framework.breach-doesnt-composeip:source.breach-doesnt-compose-ebookip:framework.architecture-not-vibesip:framework.hidden-gates-frameworkip:source.hidden-gates-ebookip:source.security-reviewer-method-ebookip:concept.architectural-containmentip:concept.runtime-containmentip:concept.provenanceip:concept.verification-boundaryip:concept.sandboxed-executionip:concept.execution-attestationip:concept.governance-as-architectureip:concept.padded-cell-agent-architectureip:concept.validation-gated-llm-extractionip:concept.verbatim-source-evidence-anchoringip:concept.ephemeral-source-ai-reviewip:framework.agent-provenance-stackip:source.agent-provenance-stackip:framework.two-leashesip:source.two-leashes-ground-the-cognition-constrain-the-execution-ebookip:framework.decision-authority-infrastructureip:source.governance-as-codeip:source.compliance-cosplayip:source.the-governance-stackradar:concept.software-supply-chainradar:concept.supply-chain-securityradar:concept.npm-supply-chainradar:concept.developer-supply-chainradar:concept.code-reviewradar:concept.ai-code-reviewradar:concept.credential-theftradar:concept.credential-securityradar:concept.credential-isolationradar:concept.ai-assisted-securityradar:concept.security-agentsradar:concept.dependency-securityradar:concept.vulnerability-researchradar:git-yard-backdoor-detectionradar:subql-common-npm-compromiseradar:ghostaction-typosquatting-supply-chainradar:arrayref-crates-supply-chain-compromiseradar:git-postcheckout-credential-theftradar:keycloak-reset-bypass-cve-2026-18963radar:keycloak-reset-credentials-takeoverradar:omarchy-any-process-root-escalationradar:mikrotrick-unauthenticated-ssh-takeoverradar:sourcehut-build-log-xssradar:claude-subscriber-token-theftradar:github-copilot-review-resolutionradar:harnesseval-code-review-gainsradar:copilot-review-skills-mcp-validationradar:openai-codex-auto-reviewradar:nitpicker-self-hosted-pr-reviewradar:proval-local-code-reviewradar:rudder-spec-derived-agent-testsradar:aisle-six-curl-cvesradar:google-agentic-source-review-securityradar:palo-alto-continuous-ai-defenseradar:cyberstrike-offensive-security-harnessradar:sentinel-scan-agent-red-team-auditradar:vibeguard-ai-code-security-linterradar:safer-dependencies-claude-code-auditingradar:augur-hidden-content-scannerradar:acs-local-skill-risk-catalogradar:skillpreflight-agent-skill-scoringradar:favz-github-agent-config-censusradar:mcp-unversioned-tool-drift
queries asked of Scott's wikis
- supply-chain security malicious PR detection
- code review automation hidden payload detection
- developer tooling compromise account takeover
- open source dependency risk monitoring
- AI-assisted security review malicious code
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 530h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion
How the heat travelled
pace: p9 vs 1032 stories at the 336h mark (now 530h old) β behind addom-local-coding-harness (0.5x)
Evidence (2) β β canonical anchor
| source | object | author | score | comments |
| π§ hn β | Security: PolinRider malware detected in two open PRs (#7716, #10321)Retrieved article excerptOpen article Β· Retrieved 2026-09-21T10:22:33.066959+00:00 [shadcn-ui](https://github.com/shadcn-ui)
/
**[ui](https://github.com/shadcn-ui/ui)**
Public
- ### Uh oh!
There was an error while loading. [Please reload this page](https://github.com/shadcn-ui/ui/issues/11971).
- [Notifications](https://github.com/login?return_to=%2Fshadcn-ui%2Fui) You must be signed in to change notification settings
- [Fork
10.9k](https://github.com/login?return_to=%2Fshadcn-ui%2Fui)
- [Star
124k](https://github.com/login?return_to=%2Fshadcn-ui%2Fui)
# Security: PolinRider malware detected in two open PRs (#7716, #10321)Β #11971
New issue
Copy link
New issue
Copy link
Open
Open
[Security: PolinRider malware detected in two open PRs (#7716, #10321)](https://github.com/shadcn-ui/ui/issues/11971#top)#11971
Copy link
## Description
[@6mile](https://github.com/6mile)
[6mile](https://github.com/6mile)
opened [on Sep 20, 2026](https://github.com/shadcn-ui/ui/issues/11971#issue-5517382099)
Issue body actions
## Security Alert
PolinRider malware (DPRK-attributed, Lazarus/Contagious Interview cluster) has been detected in **two independent open pull requests** against this repository.
### Affected PRs
**PR [#7716](https://github.com/shadcn-ui/ui/pull/7716)** ("[bug]: Calendar year, month dropdown height issue [#7680](https://github.com/shadcn-ui/ui/issues/7680)") β submitted from `shakin-shahria/ui`
- Touches `apps/v4/postcss.config.mjs`, `templates/monorepo-next/apps/web/postcss.config.mjs`, `templates/monorepo-next/packages/ui/postcss.config.mjs`, plus several `tailwind.config.js` test fixtures
- Payload verified present in the diff (obfuscated code appended after the legitimate config content)
**PR [#10321](https://github.com/shadcn-ui/ui/pull/10321)** ("feat: Image upload component") β submitted from `stefann01/ui`
- Touches `apps/v4/postcss.config.mjs` and multiple `postcss.config.mjs`/`tailwind.config.js` files across templates and test fixtures
- Payload verified present in the diff
### Indicators
- Marker: `global.i="A#-..."` (e.g. `A9-3443-2`) β a payload variant using javascript-obfuscator.io-style hex/opcode packing, internally remapped to a `global['_V']` reference
- Execution via `eval`/`spawn`, C2 over rotating public Ethereum JSON-RPC endpoints
- Appended after otherwise-legitimate config content, easy to miss in a large diff
### Remediation
1. Do not merge PR [[bug]: Calendar year, month dropdown height issue #7680Β #7716](https://github.com/shadcn-ui/ui/pull/7716) or [feat: Image upload componentΒ #10321](https://github.com/shadcn-ui/ui/pull/10321) as-is
2. Strip the postcss/tailwind config changes from both PRs before considering any legitimate portions
3. Reach out to both account owners (`shakin-shahria`, `stefann01`) to check for compromise β this is consistent with account takeover, not necessarily malicious intent from the original account owner
### References
- <https://opensourcemalware.com>
- Reported via automated threat hunting
Reactions are currently unavailable
## Activity
[Sign up for free](https://github.com/signup?return_to=https://github.com/shadcn-ui/ui/issues/11971) **to join this conversation on GitHub.** Already have an account? [Sign in to comment](https://github.com/login?return_to=https://github.com/shadcn-ui/ui/issues/11971)
## Metadata
## Metadata
### Assignees
No one assigned
### Labels
No labels
No labels
### Type
No type
### Projects
No projects
### Milestone
No milestone
### Relationships
None yet
### Development
No branches or pull requests
## Issue actions
- Open in GitHub Copilot app | fr0th | 1 | 0 |
| π§ echo.github | Reports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro | 6mile | β | β |
Interpretation history
2026-10-10T09:29:37Z
grounded: converges/high β This case is a live, high-profile instance of the exact transitive supply-chain compromise Scott's 'Breach Doesn't Compose' framework argues is inevitable when
2026-09-21T14:12:15Z
anchor promoted to claim owner's artifact: echo.github.105eef86ca -> hn.story.49785327 β The GitHub security issue directly identifies the two pull requests and payload indicators tracked by the existing case.
2026-09-21T10:24:16Z
case created β A specific report identifies allegedly live malicious contributions in a widely used repository, warranting prompt confirmation and remediation tracking.
Decision trace
- 10-10 20:29groundThis case is a live, high-profile instance of the exact transitive supply-chain compromise Scott's 'Breach Doesn't Compose' framework argues is inevitable when systems rely on revi
- 09-22 00:12promote_anchorThe GitHub security issue directly identifies the two pull requests and payload indicators tracked by the existing case.
- 09-21 21:21pushReports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro β Security reporter 6mile alleges two open shadcn/ui pull r
- 09-21 21:21alert_routeReports payloads verified in the diffs of PRs #7716 and #10321 and recommends withholding merge and checking contributor accounts for compro β Security reporter 6mile alleges two open shadcn/ui pull r