PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions
PolinRider: North Korea-Linked Supply Chain Campaign Expands (TL-2026-1120), also tracked as PolinRider Rides Again, is a critical-severity supply-chain compromise, first published 2026-07-01. It is attributed to Contagious Interview (North Korea) with high confidence, affects npm, Inc. / Node.js Foundation npm registry packages, maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-1120
- Threat ID
- TL-2026-1120
- Also known as
- PolinRider Rides Again, TasksJacker, Operation PolinRider
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-07-01
- Last reviewed
- 2026-07-01
- Attribution
- Contagious Interview
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- software development, government administration, defense, financial services, cybersecurity, cryptocurrency web3
- Target regions
- Global, North America, South Asia
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in PolinRider: North Korea-Linked Supply Chain Campaign Expands
Malware and tooling: BeaverTail - S1246, DEV#POPPER, InvisibleFerret - S1245, OmniStealer
North Korean state-sponsored threat actors tied to the Contagious Interview / Famous Chollima cluster are running an expanding supply-chain campaign, PolinRider, that has published 162 malicious release artifacts across 108 packages and extensions on npm, Packagist, Go modules, and the Chrome Web Store. Loaders are hidden via whitespace padding, fake .woff2 font files, and invisible Unicode padding, triggered through malicious VS Code task files and git history rewriting, and use public blockchain RPC infrastructure (TRON, Aptos, BNB Smart Chain) as an immutable C2 dead-drop to fetch DEV#POPPER and OmniStealer for credential, browser-data, and crypto-wallet theft.
How PolinRider: North Korea-Linked Supply Chain Campaign Expands works
PolinRider is an active, expanding supply-chain compromise campaign attributed to North Korean (DPRK) state-sponsored threat actors operating under the broadly-tracked Contagious Interview / Famous Chollima activity cluster (also documented by MITRE ATT&CK as Group G1052, alias DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, and TAG-121). As of the 2026-07-01 Socket.dev disclosure, the campaign has published 162 malicious release artifacts across 108 unique packages and extensions spanning npm, Packagist (Composer/PHP), Go modules, and the Chrome Web Store, building on independent tracking by the OpenSourceMalware research team, which had separately confirmed 1,951 compromised GitHub repositories belonging to 1,047 unique owners as of April 2026 under the same threat-actor toolchain, including a merged sub-campaign known as TasksJacker.
Initial access is achieved through two overlapping vectors: (1) classic Contagious Interview social engineering, in which a fake company persona (e.g., 'ShoeVista') issues a trojanized MERN-stack take-home coding assessment to job-seeking developers, and (2) direct compromise of legitimate GitHub maintainer accounts and Packagist namespaces (e.g., Xpos587, 7span/sevenspan, Artiffusion-Inc), potentially via expired-domain takeover or account-recovery abuse, allowing the actor to publish trojanized package versions trusted by downstream consumers.
The loader itself is obfuscated JavaScript hidden using whitespace padding that pushes malicious code beyond the default editor viewport, fake .woff2 font files that are actually JavaScript (file-type masquerading), and invisible Unicode byte sequences (zero-width space U+200B / variation selectors) used as further padding/obfuscation. Execution is triggered automatically via malicious .vscode/tasks.json files configured with runOn: folderOpen and hide: true, or via postinstall hooks that append obfuscated code to common build config files (tailwind.config.js, postcss.config.mjs, vite.config.js, eslint.config.mjs, next.config.mjs, babel.config.js, astro.config.mjs). The actor further evades detection and complicates incident response by rewriting git history, force-pushing and back-dating commits so tampered code appears older than it is, rendering the visible commit history and GitHub UI unreliable for triage.
Once triggered, the loader uses a blockchain dead-drop C2 mechanism: it queries public RPC infrastructure for TRON (trongrid.io / api.trongrid.io), falling back to Aptos (fullnode.mainnet.aptoslabs.com) and BNB Smart Chain (bsc-dataseed.binance.org, bsc-rpc.publicnode.com), extracting attacker-controlled data embedded in transaction input fields after a '?.?' marker, XOR-decoding the extracted payload, and executing it inline via eval() or in a detached node -e process. Because blockchain transactions are immutable and append-only, this dead-drop infrastructure cannot be taken down by defenders or registrars. Observed follow-on payloads include DEV#POPPER (command execution and socket.io-client-based C2), OmniStealer (a Python-based stealer targeting 60+ browser crypto-wallet extensions, password managers, cloud storage credentials, and browser session data, linked to roughly 300,000 stolen credentials per Ransom-ISAC), BeaverTail (a JavaScript infostealer delivered via the tailwind-autoanimation package), and InvisibleFerret (a cross-platform modular RAT, MITRE ATT&CK S1245).
The campaign forms part of a broader, coordinated 2026 wave of DPRK-linked open-source supply-chain operations targeting multiple ecosystems in parallel, including the PHP/Packagist-focused 'JADESNOW' activity and the PyPI-focused 'Shai-Hulud' (Miasma Worm) campaign, indicating a deliberate, resourced effort to compromise software supply chains across every major package ecosystem simultaneously. Confirmed victims include government agencies in Bangladesh and the United States, cybersecurity firms, and defense contractors, in addition to individual software developers targeted directly through fake recruitment lures.
MITRE ATT&CK techniques used in TL-2026-1120
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery
Persistence
T1098 Account Manipulation; T1176 Software Extensions
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Resource Development
Affected products and versions in PolinRider: North Korea-Linked Supply Chain Campaign Expands
- npm, Inc. / Node.js Foundation — npm registry packages
Vulnerable versions: tailwindcss-style-animate <=1.1.6; tailwind-mainanimation (all published versions); tailwind-autoanimation (all published versions)
Fixed in: No fixed version; malicious releases removed/scrubbed by npm registry operators, treat all prior installs as compromised - Packagist / Composer — sevenspan namespace PHP packages
Vulnerable versions: 7span/react-list and related sevenspan/7span-namespace packages; roberts/leads
Fixed in: Partial remediation on 2026-05-16 removed fake .woff2 fonts only; secondary payloads in vite.config.js/eslint.config.js remained unpatched - Go Modules (proxy.golang.org) — Go module packages
Vulnerable versions: 80 identified Go modules, including Xpos587/git2md and Xpos587/markfetch
Fixed in: No comprehensive fix confirmed; Go module proxy cache may still serve compromised versions - Google — Chrome Web Store extension
Vulnerable versions: 1 identified malicious Chrome extension (identifier not disclosed in public reporting)
Fixed in: Removal status not confirmed as of 2026-07-01
Remediation for PolinRider: North Korea-Linked Supply Chain Campaign Expands
Patches
- No vendor patch is applicable; remove malicious package versions/extension and republish clean releases from verified maintainer accounts with MFA re-enrolled.
- npm has scrubbed the live malicious release of tailwind-mainanimation; verify removal status of tailwindcss-style-animate, tailwind-autoanimation, and the sevenspan Packagist packages directly with registry maintainers.
Immediate actions
- Audit all repositories and CI/CD pipelines for anomalous .vscode/tasks.json entries, especially any using runOn: folderOpen combined with hide: true.
- Search dependency trees for tailwindcss-style-animate, tailwind-mainanimation, tailwind-autoanimation, and any sevenspan/7span-namespace Packagist package or Xpos587-authored Go module; remove and rotate any credentials used on systems where they were installed.
- Block outbound requests from developer workstations and CI runners to blockchain RPC endpoints (api.trongrid.io, trongrid.io, fullnode.mainnet.aptoslabs.com, aptoslabs.com, bsc-dataseed.binance.org, bsc-rpc.publicnode.com) unless explicitly required by business logic.
- Rotate GitHub tokens, SSH keys, cloud (AWS/Azure/GCP) credentials, and browser-saved passwords on any machine that opened a suspect repository in VS Code or ran npm/composer/go install against a flagged package.
Workarounds
- Pin dependencies to known-good, previously audited versions/hashes via lockfiles and verify against the OpenSourceMalware IOC list before upgrading.
- Treat any development environment that opened a ShoeVista-style take-home test repository, or any repository under Xpos587, 7span/sevenspan, or Artiffusion-Inc, as compromised until forensically cleared.
Longer-term hardening
- Enforce mandatory code review and CI-based static/dynamic scanning of dependency updates, with particular attention to trailing-whitespace-padded lines and non-standard binary/font assets containing JavaScript.
- Disable VS Code workspace auto-run task execution (runOn: folderOpen) by default via organizational policy/extension settings, requiring explicit developer approval before running workspace-defined tasks.
- Require signed commits and branch protection with force-push disabled on default branches to prevent git-history rewriting.
- Deploy EDR/behavioral monitoring on developer endpoints capable of flagging Node.js/Python processes making outbound connections to public blockchain RPC infrastructure or socket.io channels shortly after IDE launch.
Weaknesses (CWE) in PolinRider: North Korea-Linked Supply Chain Campaign Expands
CWE-506, CWE-829, CWE-494
Timeline of PolinRider: North Korea-Linked Supply Chain Campaign Expands
- The DeceptiveDevelopment/Contagious Interview activity cluster (tracked by MITRE ATT&CK as Group G1052) is assessed as active since at least 2023, targeting software developers across Windows, Linux, and macOS for financial gain.
- Anti-dated (backdated) malicious commits first appear in 7span/sevenspan-namespace repositories as part of PolinRider git-history-rewriting tradecraft.
- The OpenSourceMalware research team first publicly identifies and names the PolinRider DPRK threat actor and campaign after finding obfuscated JavaScript payloads implanted across hundreds of public GitHub repositories.
- Related reporting documents the broader Contagious Interview campaign spreading staged RAT payloads across five open-source ecosystems.
- OpenSourceMalware publishes the 'PolinRider Rides Again' follow-up, confirming 1,951 compromised GitHub repositories across 1,047 unique owners and documenting the campaign's merger with the TasksJacker sub-campaign (VS Code tasks.json curl-pipe-to-shell payloads).
- 7span maintainers perform partial remediation, removing fake .woff2 font files but missing secondary loader payloads hidden in vite.config.js and eslint.config.js.
- The related 'JADESNOW' Famous Chollima activity targeting PHP developers via a compromised Packagist package is publicly reported.
- The related 'Shai-Hulud' Miasma Worm campaign targeting the PyPI ecosystem is reported as part of the same broader North Korea-linked open-source supply-chain wave.
- Synchronized modifications occur across multiple Xpos587-controlled repositories within the same narrow window (10:00 UTC), indicating coordinated account takeover rather than legitimate maintenance.
- Socket.dev publishes the PolinRider expansion report documenting 162 malicious release artifacts across 108 packages/extensions spanning npm, Packagist, Go modules, and the Chrome Web Store; the Malpedia library entry is published the same day.
Sources cited for PolinRider: North Korea-Linked Supply Chain Campaign Expands
- PolinRider: North Korea-Linked Supply Chain Campaign Expands
- Malpedia Library entry - PolinRider
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
- Active Exploitation Alert: North Korean PolinRider Supply Chain Attack Targets npm, Packagist, Go Modules, and Chrome Extensions
- Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
- OpenSourceMalware/PolinRider - technical dossier
- PolinRider Rides Again: North Korean Attack Expands Across GitHub
- PolinRider: DPRK Threat Actor That Compromised Hundreds of GitHub Repos Is Unmasked
- DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')
- Omnistealer uses the blockchain to steal everything it can
- Contagious Interview, DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, Group G1052
- InvisibleFerret, Software S1245
- Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
- RATatouille: A Malicious Recipe Hidden in rand-user-agent (Supply Chain Compromise)
Threats related to PolinRider: North Korea-Linked Supply Chain Campaign Expands
- PolinRider DPRK Supply-Chain Campaign: Confirmed GitHub Footprint Grows 6.5x Since March (JADESNOW/Beavertail/InvisibleFerret Loaders, DEV#POPPER & OmniStealer Payloads)
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
- PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer)
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT and Credential Stealer
- North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source Packages
- PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files (tailwind.config.js et al.)
Detection coverage for TL-2026-1120
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1120 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1120
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.