North Korean Intelligence Expands PolinRider Supply Chain Campaign Across 108 Open Source Packages
Socket Threat Research, in a July 1 report, identified 162 malicious release artifacts across 108 packages and extensions tied to the PolinRider campaign, which it linked to North Korea's
The campaign's move beyond npm into 80 Go modules, ten Packagist packages, and a Chrome extension shows North Korean operators scaling account-takeover tradecraft across ecosystems rather than exploiting a single registry's weaknesses. Git history rewriting and force pushes defeat the standard defender workflow of trusting a repository's visible commit log, forcing reliance on GitHub Activity logs and registry publish records instead. The loader architecture separates initial compromise from payload delivery, so DEV#POPPER and OmniStealer represent current capability rather than a fixed toolset. Gaps in the Xpos587 case, no malicious PyPI or npm releases despite repository access, indicate credential or platform-control limits rather than restraint.
4 sources
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems -
Socket - North Korean PolinRider supply chain attack targets 108 unique repos -
SC Media - North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign -
The Hacker News - North Korean Hackers Target Open Source Developers in Supply Chain Attacks -
SecurityWeek