PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files (tailwind.config.js et al.) — Threadlinqs Intelligence
As of 2026-07-07, PolinRider: DPRK Supply-Chain Campaign Hides BeaverTail/InvisibleFerret Malware in JS Build Config Files (tailwind.config.js et al.) is a critical-severity supply chain threat attributed to PolinRider (DPRK (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 53 indicators of compromise.
Threat ID: TL-2026-1143 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: PolinRider (DPRK · North Korea (DPRK) · FINANCIAL
A DPRK/Lazarus-aligned actor tracked as PolinRider compromises npm, Packagist, and Go module packages whose postinstall/build hooks append obfuscated JavaScript to common build config files
PolinRider is a DPRK/Lazarus-aligned supply-chain operation, first flagged by the OpenSourceMalware (OSM) research team in March 2026, that merges the previously tracked 'TasksJacker' and 'Contagious Interview' activity clusters. The actor compromises legitimate npm, Packagist, and Go module packages (and, in the July 2026 wave, a Chrome Web Store extension) so that their install/build lifecycle silently appends obfuscated JavaScript to the end of widely-used JS/TS build configuration files — tailwind.config.js, postcss.config.mjs, eslint.config.mjs, next.config.mjs, babel.config.js, and app.js — after the file's legitimate content, so the payload executes automatically the next time any build tool (webpack, Vite, Next.js, PostCSS, ESLint) imports the module. A second delivery vector abuses `.vscode/tasks.json` with `"runOn": "folderOpen"` to gain code execution the moment a victim opens an infected repository folder in VS Code, and a third vector masquerades JavaScript payloads as binary `.woff2` font files.
Once triggered, the loader fingerprints the host OS, then reaches out to public blockchain RPC infrastructure (TRON, Aptos, and BNB Smart Chain — the 'EtherHiding'/blockchain dead-drop technique also seen elsewhere in DPRK tradecraft) to retrieve an encrypted second-stage payload, decrypts it with an embedded XOR key, and executes it via `eval()`. This delivers an updated variant of the BeaverTail JavaScript stager, which in turn downloads a Python interpreter and the InvisibleFerret cross-platform RAT (a three-component Python backdoor: downloader, main payload with fingerprinting/remote-control/keylogging/exfiltration, and a dedicated browser-credential stealer). Follow-on payloads observed in the campaign include the Node.js RAT DEV#POPPER (multi-operator command queues, socket.io-client C2, `/verify-human/[VERSION]` heartbeat and `/u/f` file-upload endpoints, Node.js module-search-order hijacking via a hidden `.node_modules` folder, and sandbox/CI evasion) and OmniStealer (browser data, session cookie, and cryptocurrency wallet exfiltration, also over socket.io-client).
The actor further obfuscates its footprint using a 'Glassworm' technique — invisible zero-width Unicode and Private-Use-Area characters embedded in source to hide encrypted bytecode from code review and diff tools — and a 'ForceMemo' technique that uses stolen GitHub tokens to rebase malicious commits into repository history with falsified author/committer dates, evading standard review. A destructive companion behavior observed on 2026-05-27 force-pushes a single collapsed commit across all branches of compromised repositories, destroying divergent branch history (recoverable only via the GitHub Events API within its ~48-hour retention window).
Campaign scale grew from 675 repositories / 352 owners (2026-03-08) to 1,951 repositories / 1,047 owners (2026-04-11), with a compromised GitHub account (Xpos587) and organization (7span/sevenspan) used to push malicious Go modules and Packagist packages, and a synchronized bulk-modification wave across the Xpos587 account on 2026-06-23 at 10:00 UTC. A subsequent, distinct wave publishing 108 new malicious packages/extensions (162 release artifacts: 19 npm libraries, 10 Packagist packages, 61 Go modules... and 80 Go modules per Socket's count, plus one Chrome extension) across npm, Packagist, Go modules, and the Chrome Web Store was reported 2026-07-06/07. PolinRider overlaps infrastructure, tooling (AnyDesk, Astrill VPN), and an operator email (hundredup2023@gmail.com) with the related PurpleBravo/PurpleDelta clusters, and is attributed with high confidence to DPRK state-sponsored actors tracked elsewhere as Lazarus Group, Famous Chollima, Void Dokkaebi, CL-STA-0240, and Tenacious Pungsan — part of the broader 'Contagious Interview' operation that also uses fake recruiter personas and weaponized take-home coding assessments to compromise individual developers directly.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494, CWE-1357
Target sectors: technology, software development, cryptocurrency, financial services, information technology services, government administration, defense industrial base
Target regions: Global, North America, South Asia, Europe
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 53 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, T1583.001, T1585.001, T1587.001, T1608.001, T1588.002, T1195, T1195.001, T1195.002, T1566.002, T1566.003