Trojan Hid in Fake Font File, Compromised 18 Repos Over 77 Days Undetected

A developer discovered a trojan on 6 September 2026 after an antivirus quarantined a 32 KB file disguised as a Font Awesome font in a project's public folder. The malware had been active since 22 June, silently operating for 77 days across 18 repositories spanning three GitHub organisations, including client projects. It worked by hiding malicious JavaScript in VS Code task configuration files and build config files, executing automatically whenever a folder was opened or a build was triggered. The trojan had access to SSH keys, environment files containing payment and database credentials, browser-saved passwords, and deployment secrets throughout the infection period. Remediation required not just cleaning the affected machines but revoking all SSH keys, tokens, and credentials that may have been copied during the intrusion.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in