Threat Intelligence / Actor / PolinRider
PolinRider
As of 2026-07-21, PolinRider is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning supply chain. Also known as UNC5342, js.jadesnow operator, JADESNOW, PolinRider (DPRK / Contagious Interview / Lazarus cluster).
Also known as: PolinRider, UNC5342, js.jadesnow operator, JADESNOW, PolinRider (DPRK / Contagious Interview / Lazarus cluster), Contagious Interview, TasksJacker, WaterPlum, Nickel Alley, Lazarus Group, DeceptiveDevelopment
Tracked threats
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign — HIGH
- astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow) — HIGH
- PolinRider — DPRK Supply-Chain Campaign Compromises 1,951 GitHub Repos via Malicious npm Packages, VS Code tasks.json Auto-Run, and TRON/Aptos/BSC Blockchain Dead-Drop C2 — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →