Skip to content
View finom's full-sized avatar

Sponsoring

@yusukebe
@oliverbutler
@dai-shi

Block or report finom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
finom/README.md

⚠️ Security notice — PolinRider supply-chain compromise (resolved)

I was one of ~1,047 GitHub owners hit by the PolinRider DPRK supply-chain attack documented at OpenSourceMalware/PolinRider. An obfuscated JS payload was silently appended to config files in four of my repos by a malicious npm package or VS Code extension — I didn't commit it and had no idea it was there.

Affected repos (now cleaned and pushed):

A near-miss was also caught in review on finom/prisma-zod-generator.

If you cloned or npm installed from any of these before the cleanup

Please run the OSM scanner (polinrider-scanner.sh) and follow the mitigation steps — audit your config files, delete any temp_auto_push.bat, and rotate build-environment secrets.

Everything on my side is fixed. Apologies to anyone exposed through my repos, and thanks for your patience — stupid situation, but handled.

— Andrey


Hi there 👋

My name is Andrey Gubanov. I live in the open-source universe since 2011. Most of my projects can be found on opensource.gubanov.eu. Feel free to follow my Github profile and star my repos!

GitHub Stats

Pinned Loading

  1. vovk vovk Public

    🐺 Back-end Framework for Next.js App Router. One codebase → type-safe clients, OpenAPI, and AI tools

    TypeScript 52

  2. check-imports check-imports Public

    Node.js tool that helps to control validity of imports and dependencies in a TypeScript project

    TypeScript 29 4