socket-dev · Crawled Jul 5, 2026
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
7 IoCs 2 Actors
Read original article ↗
AI Summary
PolinRider is a North Korea-linked supply chain campaign targeting developer ecosystems, including npm, Packagist, Go modules, and Chrome extensions. The threat actors compromise maintainer accounts, modify legitimate repositories with obfuscated JavaScript loaders, and use Git history rewriting to conceal malicious changes. These loaders retrieve encrypted second-stage payloads from blockchain infrastructure, execute them via eval(), and have delivered malware such as DEV#POPPER and OmniStealer. The campaign remains active, with ongoing compromises across multiple open source platforms.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 7 extracted
MITRE ATT&CK TTPs 16 techniques
T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1083 File and Directory Discovery · Discovery T1114 Email Collection · Collection T1482 Domain Trust Discovery · Discovery T1490 Inhibit System Recovery · Impact T1555 Credentials from Password Stores · Credential Access T1005 Data from Local System · Collection T1027 Obfuscated Files or Information · Defense Evasion T1056.001 Keylogging · Collection T1071.003 Mail Protocols · Command And Control T1082 System Information Discovery · Discovery T1113 Screen Capture · Collection T1123 Audio Capture · Collection T1566 Phishing · Initial Access