Adversary Intelligence — 2026-07-08

North Korean Intelligence Expands PolinRider Supply Chain Campaign Across 108 Open Source Packages

BLUFNorth Korean operators expanding account-takeover supply chain attacks across four distinct package ecosystems undercuts the assumption that registry-specific defenses can contain this threat.

Socket Threat Research, in a July 1 report, identified 162 malicious release artifacts across 108 packages and extensions tied to the PolinRider campaign, which it linked to North Korea's Contagious Interview/Famous Chollima activity cluster 1. Compromise traces span 80 Go modules, 10 Packagist packages, and one Chrome extension, marking an expansion beyond the campaign's original npm footprint 123. Socket reported the actors compromise maintainer accounts, plant obfuscated JavaScript loaders hidden in whitespace padding or fake .woff2 font files, and use Git history rewriting, including force pushes and anti-dated commits, to disguise the changes 1. Socket documented one case, the Xpos587 GitHub account, where multiple repositories were modified in the same window on June 23 and malicious Go module versions followed 1. Deobfuscated payloads observed included DEV#POPPER and OmniStealer, which contact TRON, Aptos, and BNB Smart Chain infrastructure for second-stage delivery 1.

Analysis
The campaign's move beyond npm into 80 Go modules, ten Packagist packages, and a Chrome extension shows North Korean operators scaling account-takeover tradecraft across ecosystems rather than exploiting a single registry's weaknesses. Git history rewriting and force pushes defeat the standard defender workflow of trusting a repository's visible commit log, forcing reliance on GitHub Activity logs and registry publish records instead. The loader architecture separates initial compromise from payload delivery, so DEV#POPPER and OmniStealer represent current capability rather than a fixed toolset. Gaps in the Xpos587 case, no malicious PyPI or npm releases despite repository access, indicate credential or platform-control limits rather than restraint.
4 sources
  1. PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems - Socket
  2. North Korean PolinRider supply chain attack targets 108 unique repos - SC Media
  3. North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign - The Hacker News
  4. North Korean Hackers Target Open Source Developers in Supply Chain Attacks - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE