PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions — Threadlinqs Intelligence
As of 2026-07-05, PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions is a critical-severity supply chain threat attributed to Contagious Interview (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1120 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: Contagious Interview · North Korea (DPRK) · FINANCIAL
North Korean state-sponsored threat actors tied to the Contagious Interview / Famous Chollima cluster are running an expanding supply-chain campaign, PolinRider, that has published 162 malicious
PolinRider is an active, expanding supply-chain compromise campaign attributed to North Korean (DPRK) state-sponsored threat actors operating under the broadly-tracked Contagious Interview / Famous Chollima activity cluster (also documented by MITRE ATT&CK as Group G1052, alias DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, and TAG-121). As of the 2026-07-01 Socket.dev disclosure, the campaign has published 162 malicious release artifacts across 108 unique packages and extensions spanning npm, Packagist (Composer/PHP), Go modules, and the Chrome Web Store, building on independent tracking by the OpenSourceMalware research team, which had separately confirmed 1,951 compromised GitHub repositories belonging to 1,047 unique owners as of April 2026 under the same threat-actor toolchain, including a merged sub-campaign known as TasksJacker.
Initial access is achieved through two overlapping vectors: (1) classic Contagious Interview social engineering, in which a fake company persona (e.g., 'ShoeVista') issues a trojanized MERN-stack take-home coding assessment to job-seeking developers, and (2) direct compromise of legitimate GitHub maintainer accounts and Packagist namespaces (e.g., Xpos587, 7span/sevenspan, Artiffusion-Inc), potentially via expired-domain takeover or account-recovery abuse, allowing the actor to publish trojanized package versions trusted by downstream consumers.
The loader itself is obfuscated JavaScript hidden using whitespace padding that pushes malicious code beyond the default editor viewport, fake .woff2 font files that are actually JavaScript (file-type masquerading), and invisible Unicode byte sequences (zero-width space U+200B / variation selectors) used as further padding/obfuscation. Execution is triggered automatically via malicious .vscode/tasks.json files configured with runOn: folderOpen and hide: true, or via postinstall hooks that append obfuscated code to common build config files (tailwind.config.js, postcss.config.mjs, vite.config.js, eslint.config.mjs, next.config.mjs, babel.config.js, astro.config.mjs). The actor further evades detection and complicates incident response by rewriting git history, force-pushing and back-dating commits so tampered code appears older than it is, rendering the visible commit history and GitHub UI unreliable for triage.
Once triggered, the loader uses a blockchain dead-drop C2 mechanism: it queries public RPC infrastructure for TRON (trongrid.io / api.trongrid.io), falling back to Aptos (fullnode.mainnet.aptoslabs.com) and BNB Smart Chain (bsc-dataseed.binance.org, bsc-rpc.publicnode.com), extracting attacker-controlled data embedded in transaction input fields after a '?.?' marker, XOR-decoding the extracted payload, and executing it inline via eval() or in a detached node -e process. Because blockchain transactions are immutable and append-only, this dead-drop infrastructure cannot be taken down by defenders or registrars. Observed follow-on payloads include DEV#POPPER (command execution and socket.io-client-based C2), OmniStealer (a Python-based stealer targeting 60+ browser crypto-wallet extensions, password managers, cloud storage credentials, and browser session data, linked to roughly 300,000 stolen credentials per Ransom-ISAC), BeaverTail (a JavaScript infostealer delivered via the tailwind-autoanimation package), and InvisibleFerret (a cross-platform modular RAT, MITRE ATT&CK S1245).
The campaign forms part of a broader, coordinated 2026 wave of DPRK-linked open-source supply-chain operations targeting multiple ecosystems in parallel, including the PHP/Packagist-focused 'JADESNOW' activity and the PyPI-focused 'Shai-Hulud' (Miasma Worm) campaign, indicating a deliberate, resourced effort to compromise software supply chains across every major package ecosystem simultaneously. Confirmed victims include government agencies in Bangladesh and the United States, cybersecurity firms, and defense contractors, in addition to i
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494
Target sectors: software development, government administration, defense, financial services, cybersecurity, cryptocurrency web3
Target regions: Global, North America, South Asia
References
- PolinRider: North Korea-Linked Supply Chain Campaign Expands
- Malpedia Library entry - PolinRider
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
- Active Exploitation Alert: North Korean PolinRider Supply Chain Attack Targets npm, Packagist, Go Modules, and Chrome Extensions
- Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
- OpenSourceMalware/PolinRider - technical dossier
- PolinRider Rides Again: North Korean Attack Expands Across GitHub
- PolinRider: DPRK Threat Actor That Compromised Hundreds of GitHub Repos Is Unmasked
- DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')
- Omnistealer uses the blockchain to steal everything it can
- Contagious Interview, DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, Group G1052
- InvisibleFerret, Software S1245
- Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
- RATatouille: A Malicious Recipe Hidden in rand-user-agent (Supply Chain Compromise)
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1608, T1195, T1195, T1199, T1566, T1059, T1059, T1204, T1176, T1098