PolinRider Campaign: DPRK-Linked Supply Chain Attack Infects GitHub Repositories (Campaign)
ID: 7f8a98d9-671b-59fd-bb35-5e214395f5de
STIX ID: report--7f8a98d9-671b-59fd-bb35-5e214395f5de
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-04-09
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
PolinRider — a DPRK-linked supply chain campaign — has infected over 1,900 GitHub repositories through malicious npm packages, VS Code artifacts, and injected JavaScript payloads. The attackers use obfuscated injections into project files and weaponized developer tooling, retrieve XOR-encrypted second-stage code from blockchain networks for execution via eval(), maintain persistence and remote code execution via detached processes, and rewrite Git history to hide and push malicious changes, ultimately delivering an infostealer/Beavertail variant that enables credential theft and broad downstream compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
