Activity timeline
PolinRider appears in 5 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 5 of 5 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 5 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 4 of 5 tracked threats
- T1585 Establish Accounts — Resource Developmentobserved in 4 of 5 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 5 tracked threats
- T1059.007 JavaScript — Executionobserved in 3 of 5 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 5 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 5 tracked threats
- T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 3 of 5 tracked threats
- T1552.001 Unsecured Credentials — Credential Accessobserved in 3 of 5 tracked threats
- T1587.001 Malware — Resource Developmentobserved in 3 of 5 tracked threats
- T1608 Stage Capabilities — Resource Developmentobserved in 3 of 5 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 5 tracked threats
Tracked threats
- GHAPPIER Loader: npm Supply-Chain Compromise of @dforge-core/dforge-mcp Linked to DPRK PolinRider CampaignHIGH
- Joyfill npm Packages Compromised with Blockchain C2 LoaderMEDIUM
- ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain CampaignHIGH
- astro.config.mjs Supply Chain Attack via Blockchain Dead-Drop C2 (PolinRider / js.jadesnow)HIGH
- PolinRider — DPRK Supply-Chain Campaign Compromises 1,951 GitHub Repos via Malicious npm Packages, VS Code tasks.json Auto-Run, and TRON/Aptos/BSC Blockchain Dead-Drop C2CRITICAL