Automated scan found a malicious code signature (campaign A8-1662 / obfuscated payload / disguised binary) at commit 7cf68b0.
Run: https://github.com/Lanthanum89/binary-clock/actions/runs/34053423363
Do not trust commit messages claiming removal -- in the original incident the commit titled "Remove malicious code injected into eslint.config.js" did not remove the payload, it swapped in a larger variant. Read file content directly at the current ref before concluding anything is clean.
Automated scan found a malicious code signature (campaign A8-1662 / obfuscated payload / disguised binary) at commit 7cf68b0.
Run: https://github.com/Lanthanum89/binary-clock/actions/runs/34053423363
Do not trust commit messages claiming removal -- in the original incident the commit titled "Remove malicious code injected into eslint.config.js" did not remove the payload, it swapped in a larger variant. Read file content directly at the current ref before concluding anything is clean.