North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source Packages
North Korea-Linked "Contagious Interview"/Famous Chollima (TL-2026-1111), also tracked as PolinRider, is a high-severity supply-chain compromise, first published 2026-07-05. It is attributed to WageMole (North Korea) with medium confidence, affects Xpos587 (GitHub) git2md, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1036.008), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-1111
- Threat ID
- TL-2026-1111
- Also known as
- PolinRider
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-07-05
- Last reviewed
- 2026-07-05
- Attribution
- WageMole
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, software development, cryptocurrency, finance, open source ecosystem
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in North Korea-Linked "Contagious Interview"/Famous Chollima
Malware and tooling: BeaverTail - S1246, DEV#POPPER, GolangGhost (OS X), InvisibleFerret - S1245, OmniStealer, OtterCookie, PolinRider, PylangGhost
North Korean state-linked actors tied to the Contagious Interview / Famous Chollima activity clusters compromised the Xpos587 GitHub maintainer account and other maintainers to distribute a JavaScript loader campaign dubbed PolinRider across npm, Packagist, Go module, and Chrome extension packages. The loaders deliver second-stage DEV#POPPER and OmniStealer payloads via blockchain-based (TRON, Aptos, BNB Smart Chain) dead-drop resolvers, targeting developer credentials, CI/CD secrets, and cryptocurrency wallets. Socket.dev's Threat Research Team identified 162 malicious release artifacts across 108 unique packages and extensions.
How North Korea-Linked "Contagious Interview"/Famous Chollima works
PolinRider is an ongoing JavaScript loader supply-chain campaign attributed with medium confidence to the North Korea-aligned Famous Chollima cluster (also tracked as Contagious Interview, Void Dokkaebi, DeceptiveDevelopment, Wagemole, and related aliases). The operation compromises legitimate maintainer accounts on GitHub and downstream package registries -- observed against the Xpos587 GitHub account, the Artiffusion-Inc/mirofish repository, and the 7span (sevenspan) Packagist organization -- and uses that trusted access to push obfuscated JavaScript loader code into otherwise legitimate open-source releases spanning npm, Packagist, Go modules, and at least one Chrome extension. Socket's Threat Research Team catalogued 162 malicious release artifacts across 108 unique packages, including roughly 80 Go modules, 10 Packagist packages, one Chrome extension, and a smaller set of npm packages.
The loader is concealed using two primary techniques: (1) obfuscated, whitespace-padded one-line JavaScript embedded inside legitimate-looking configuration files such as vite.config.js, eslint.config.js, and other *config.js files, positioned beyond the default editor/diff viewport so reviewers do not see it; and (2) a fully obfuscated JavaScript loader disguised as a fake .woff2 web-font asset (e.g. public/fonts/fa-solid-400.woff2), a file type security tooling commonly treats as an inert binary and skips during review. Execution is achieved without any build step or explicit developer action: a modified .vscode/tasks.json file defines a hidden task configured with "runOn": "folderOpen", which VS Code automatically executes -- passing the fake font asset to Node.js -- the moment a developer opens the compromised project folder.
Once running, the loader reaches out to blockchain RPC services on TRON, Aptos, and BNB Smart Chain, using them as an immutable, takedown-resistant dead-drop resolver to retrieve an encrypted second-stage payload. The retrieved material is decrypted with embedded XOR keys and executed via eval(). Observed second-stage payloads are DEV#POPPER, a remote-access/command-execution implant associated with the broader Famous Chollima toolset, and OmniStealer, an information stealer that targets browser-stored data and cryptocurrency wallets. Both communicate with attacker-controlled infrastructure using the socket.io-client library for command-and-control. Because the loader architecture is modular, researchers assess it is capable of delivering additional malware beyond the two payloads currently observed.
The operators additionally manipulate Git history -- using force pushes and backdated/antedated commits -- to make the malicious insertions appear older than their actual publish date, undermining the reliability of GitHub's commit-history and "last updated" indicators as a triage signal. Coordinated modification of multiple Xpos587-linked repositories (git2md, markfetch) and Artiffusion-Inc/mirofish occurred within a narrow window on 2026-06-23 at 10:00 UTC, consistent with automated, scripted publishing rather than manual, one-off tampering. The 7span/react-list Packagist package was compromised and remediated earlier, on 2026-05-16, indicating the campaign has been active across multiple waves and ecosystems over at least several months.
Attribution rests on TTP overlap with previously documented Famous Chollima / Contagious Interview activity: fake-recruiter social engineering of developers, abuse of VS Code auto-execution and workspace trust, and heavy targeting of cryptocurrency wallets, password-manager stores, and CI/CD secrets -- documented by Microsoft, CrowdStrike, Huntress, and Trend Micro in related campaigns using malware such as BeaverTail, InvisibleFerret, OtterCookie, PylangGhost, and GolangGhost. Organizations that installed any affected package version should treat the developer environment as compromised: preserve forensic artifacts, rebuild from known-good lockfiles, rotate all exposed secrets and tokens from a clean machine, and audit for hidden VS Code task auto-execution paths across all repositories.
MITRE ATT&CK techniques used in TL-2026-1111
Collection
T1005 Data from Local System; T1115 Clipboard Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036.008 Masquerade File Type; T1070.006 Timestomp; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1573.001 Symmetric Cryptography
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
Persistence
T1098 Account Manipulation; T1554 Compromise Host Software Binary
Initial Access
T1195.001 Compromise Software Dependencies and Development Tools; T1199 Trusted Relationship; T1566.002 Spearphishing Link
Credential Access
T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555 Credentials from Password Stores
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1608.001 Upload Malware
Affected products and versions in North Korea-Linked "Contagious Interview"/Famous Chollima
- Xpos587 (GitHub) — git2md
Vulnerable versions: releases published after the account takeover on 2026-06-23
Fixed in: repository remediated / commits reverted following disclosure - Xpos587 (GitHub) — markfetch
Vulnerable versions: releases published after the account takeover on 2026-06-23
Fixed in: repository remediated / commits reverted following disclosure - Artiffusion-Inc — mirofish
Vulnerable versions: release versions containing the modified vite.config.js, published around 2026-06-23
Fixed in: repository remediated following disclosure - 7span (sevenspan) — react-list (Packagist)
Vulnerable versions: release versions carrying the PolinRider loader prior to 2026-05-16
Fixed in: remediated by maintainer on 2026-05-16 - Open Source Ecosystem — npm packages (subset of 108 total affected)
Vulnerable versions: 162 malicious release artifacts across 108 packages/extensions per Socket.dev tracking
Fixed in: see Socket.dev PolinRider tracking page for per-package remediation status - Open Source Ecosystem — Go modules (~80 identified)
Vulnerable versions: compromised release versions distributed via the Go module proxy
Fixed in: see Socket.dev PolinRider tracking page for per-module remediation status - Open Source Ecosystem — Chrome extension (1 identified)
Vulnerable versions: compromised extension version distributed via the Chrome Web Store
Fixed in: see Socket.dev PolinRider tracking page for remediation status
Remediation for North Korea-Linked "Contagious Interview"/Famous Chollima
Patches
- No vendor patch applies -- remediation is removal/rollback of malicious package versions and revocation of compromised maintainer credentials, not a software patch
Immediate actions
- Audit installed dependencies (npm, Composer/Packagist, Go modules, Chrome extensions) for the specific compromised packages -- Xpos587/git2md, Xpos587/markfetch, Artiffusion-Inc/mirofish, 7span/react-list -- and any transitive dependents; remove or pin to last known-good versions
- Treat any workstation that opened an affected project folder in VS Code as compromised; isolate and forensically image before remediation
- Rotate all developer secrets from a clean machine: npm/Packagist/GitHub registry tokens, CI/CD pipeline credentials, SSH/GPG signing keys, and cloud provider credentials
- Inspect .vscode/tasks.json in all repositories for "runOn": "folderOpen" or other auto-execute task definitions and remove any unauthorized entries
- Block outbound requests to known TRON/Aptos/BSC RPC dead-drop patterns and socket.io-client C2 callbacks at the network egress layer for developer environments
Workarounds
- Disable VS Code automatic task execution or require manual approval for workspace tasks
- Use registry allow-listing and pinned, hash-verified dependencies instead of floating version ranges
- Run untrusted repository checkouts inside disposable containers/VMs without access to production secrets or wallets
Longer-term hardening
- Enforce VS Code Workspace Trust and disable automatic task execution (tasks.allowAutomaticTasks) organization-wide via policy
- Adopt SBOM generation and continuous dependency scanning (Socket, Snyk, OSV) across npm/Packagist/Go/Chrome-extension supply chains
- Require signed commits/releases and mandatory MFA plus hardware security keys for all package-registry and GitHub maintainer accounts
- Implement lockfile integrity verification and pin exact dependency versions/hashes in CI pipelines
- Segregate cryptocurrency wallet and signing-key material from developer workstations used for day-to-day coding
Weaknesses (CWE) in North Korea-Linked "Contagious Interview"/Famous Chollima
CWE-506, CWE-829, CWE-494
Timeline of North Korea-Linked "Contagious Interview"/Famous Chollima
- Famous Chollima (tracked historically by CrowdStrike as BadClone) begins operating as a financially motivated, North Korea-aligned cluster (active since at least 2018).
- The Contagious Interview campaign becomes active, using fake recruiter/technical-interview lures against software developers (Microsoft Defender Experts, active since at least December 2022).
- PylangGhost, a Python-based Windows RAT, is discovered as part of Famous Chollima's evolving toolset targeting crypto and developer victims.
- Microsoft publishes a Security Blog analysis of the Contagious Interview campaign, detailing OtterCookie, Invisible Ferret, FlexibleFerret, and BeaverTail malware families and their TTPs.
- 7span remediates the compromise of its react-list Packagist package (sevenspan namespace), which had been carrying the PolinRider loader.
- Coordinated modification of multiple repositories tied to the Xpos587 GitHub account (git2md, markfetch) and Artiffusion-Inc/mirofish occurs at 10:00 UTC, inserting the PolinRider loader via obfuscated config files and a fake .woff2 font payload.
- Socket's Threat Research Team publishes findings on the PolinRider campaign, cataloging 162 malicious release artifacts across 108 unique packages/extensions spanning npm, Packagist, Go modules, and Chrome extensions.
- Cyber Security News and other outlets report on the North Korea-linked PolinRider campaign, attributing it to the Contagious Interview / Famous Chollima activity cluster.
- The Hacker News and additional security outlets publish follow-up coverage expanding on package counts, ecosystem breakdown, and remediation guidance for affected developers.
Sources cited for North Korea-Linked "Contagious Interview"/Famous Chollima
- North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
- PolinRider: North Korea-Linked Supply Chain Campaign Expands
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- Contagious Interview: Malware delivered through fake developer job interviews
- Famous Chollima Adversary Profile
- Famous Chollima Threat Actor Profile
- Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
- Famous Chollima deploying Python version of GolangGhost RAT
- North Korea-Linked PolinRider Campaign Hits 108 Open Source Packages and Extensions
- PolinRider supply chain attack expands to Packagist ecosystem
- Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
- OpenSourceMalware/PolinRider research repository
- apache/superset issue: project targeted by the PolinRider supply-chain campaign
Threats related to North Korea-Linked "Contagious Interview"/Famous Chollima
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions
- PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files (tailwind.config.js et al.)
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)
- PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer)
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT and Credential Stealer
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview)
Detection coverage for TL-2026-1111
As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1111 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.