socket-dev · Crawled Jul 5, 2026

PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems

7 IoCs 2 Actors
Read original article ↗

AI Summary

PolinRider is a North Korea-linked supply chain campaign targeting developer ecosystems, including npm, Packagist, Go modules, and Chrome extensions. The threat actors compromise maintainer accounts, modify legitimate repositories with obfuscated JavaScript loaders, and use Git history rewriting to conceal malicious changes. These loaders retrieve encrypted second-stage payloads from blockchain infrastructure, execute them via eval(), and have delivered malware such as DEV#POPPER and OmniStealer. The campaign remains active, with ongoing compromises across multiple open source platforms.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 7 extracted

Type Value Detail
GitHub User Xpos587 Details →
GitHub Repo Xpos587/git2md Details →
GitHub Repo Xpos587/markfetch Details →
GitHub Repo Artiffusion-Inc/mirofish Details →
GitHub User 7span Details →
GitHub Repo 7span/react-list Details →
Package sevenspan Details →

MITRE ATT&CK TTPs 16 techniques