Threat Intelligence / Actor / WageMole
WageMole
As of 2026-08-25, WageMole is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 14 threats spanning supply chain, malware, apt. Also known as Famous Chollima, nickel tapestry, purplebravo, storm-1877.
Also known as: WageMole, Famous Chollima, nickel tapestry, purplebravo, storm-1877, unc5267, void dokkaebi, waterplum, Contagious Interview — DEV#POPPER, Contagious Interview (DPRK) — DEV#POPPER, PolinRider loader family, alternate hypothesis: UNC5342
Tracked threats
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT and Credential Stealer — CRITICAL
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview) — HIGH
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider Cluster) — HIGH
- OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign Leaks Its Own Operator Credentials — HIGH
- North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source Packages — HIGH
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions — CRITICAL
- PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer) — HIGH
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855) — HIGH
- Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style) — HIGH
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview) — HIGH
- Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories — HIGH
- DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning — HIGH
- Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews — HIGH
- Famous Chollima (DPRK) npm Supply Chain — Pastebin Text Steganography Dead-Drop Resolver, 17 Malicious Packages, Vercel C2 Infrastructure — HIGH
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →