ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign — Threadlinqs Intelligence
As of 2026-07-20, ChainVeil and ViteVenom Malware Linked to DPRK PolinRider Supply-Chain Campaign is a high-severity supply chain threat attributed to PolinRider (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 47 indicators of compromise.
Threat ID: TL-2026-1570 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: PolinRider · North Korea (DPRK) · ESPIONAGE
Malpedia and multiple security vendors link two blockchain-C2 malware families, ChainVeil and ViteVenom, to the North Korean (DPRK) supply-chain campaign PolinRider. ViteVenom impersonates the
PolinRider is a North Korea-linked (DPRK) open-source supply-chain campaign, assessed by OpenSourceMalware, Socket.dev, and Checkmarx researchers to be connected to the Lazarus Group ecosystem via overlaps with the Contagious Interview / Famous Chollima cluster and prior TaskJacker and Fake Font activity. The campaign has been tracked since at least December 2025 (with anti-dated commits reaching back to January 2026) and was first publicly disclosed on 2026-03-07 with 675 compromised GitHub repositories across 352 owners; by 2026-04-12 that footprint had grown to 1,951 repositories across 1,047 owners, and further supply-chain hijacking activity continued through July 2026.
Two malware families sit at the center of the most recent reporting. ChainVeil is a JavaScript RAT-delivery mechanism that uses an 'unprecedented' four-tier blockchain-based command-and-control architecture spanning the Tron blockchain (primary payload retrieval), Aptos (fallback address for backup delivery), and Binance Smart Chain (encrypted payload storage embedded in transaction input fields). ChainVeil was distributed via unscoped npm typosquats (e.g., 'rate-limit-flexible'). ViteVenom, identified by Checkmarx researchers, is a direct expansion of ChainVeil that instead uses scoped package names impersonating the legitimate '@vitejs/*' npm namespace to lend an air of authenticity to seven malicious packages published between 2026-06-29 and 2026-07-03: @uw010010/vite-tree, @vite-tab/tab, @vite-ln/build-ts, @vite-mcp/vite-type, @vite-pro/vite-ui, @vitets/vite-ts, and @vite-ts/vite-ui. ChainVeil and ViteVenom share tier-2 C2 infrastructure -- identical Tron wallet and Aptos account addresses feeding into the same Binance Smart Chain transaction used to deliver the RAT payload -- and are attributed via cryptocurrency wallet analysis to an actor cluster tracked as 'SuccessKey', assessed to be linked to PolinRider and, transitively, to DPRK state-directed activity.
The ViteVenom/ChainVeil infection chain executes malicious code at package IMPORT time rather than npm install time, which helps evade install-time scanners: the payload first queries the Tron blockchain for the latest attacker wallet transaction, decodes the transaction data to obtain a Binance Smart Chain transaction hash, retrieves an encrypted second-stage payload from that BSC transaction's input field, and decrypts it using a hard-coded key. If the blockchain resolution path fails, a fallback mechanism retrieves the RAT directly over HTTP. The delivered RAT provides reverse shell access, credential harvesting, file exfiltration, persistent backdoor injection, and unauthorized modification of shell profile files (.bashrc, .zshrc, .profile) to achieve persistence. Activity consistent with this cluster was observed as early as 2026-02-27.
The wider PolinRider operation (which OpenSourceMalware and Socket.dev track as the umbrella campaign encompassing ChainVeil/ViteVenom) relies on a social-engineering front: operators pose as recruiters or collaborators on LinkedIn, GitHub, and freelance platforms using fabricated companies and AI-generated profiles, delivering weaponized take-home 'interview' coding tests. Two named lure templates have been documented: 'ShoeVista', a fake Tailwind CSS e-commerce interview exercise responsible for at least 34 developer uploads of the trojanized tailwindcss-style-animate package (and related variants tailwind-mainanimation, tailwind-autoanimation, tailwindcss-typography-style, tailwindcss-style-modify, tailwindcss-animate-style); and 'StakingGame', a fake blockchain/VS Code project template (UUID e9b53a7c-2342-4b15-b02d-bd8b8f6a03f9). Malicious JavaScript loaders are appended -- after whitespace padding to hide the code from casual review -- to legitimate-looking configuration files such as postcss.config.mjs, tailwind.config.js, eslint.config.mjs, next.config.mjs, babel.config.js, vite.config.js, and app.js. A secondary concealment technique embeds obfusca
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494
Target sectors: technology, software-development, open-source-ecosystem, cryptocurrency, finance
Target regions: Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 47 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1585, T1587.001, T1583.006, T1586, T1195.002, T1195.001, T1566.003, T1199, T1204.002, T1059.007