logo

A Developer's Guide to Getting Rid of PolinRider

ID: 315f8066-6906-55dd-bea5-9e3e94c209bd

STIX ID: report--315f8066-6906-55dd-bea5-9e3e94c209bd

Feed Name: OpenSourceMalware Blog

Threat Score
90/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

PolinRider is a DPRK-run malware campaign targeting individual software developers via booby-trapped VS Code tasks, typosquatted/npm trojan packages, and infected forks/PRs; it steals credentials (browser, SSH, cloud, registry tokens, etc.), self-propagates across repos and registries using victim credentials, and persists via local propagation scripts and blockchain-based C2. The post details infection vectors, why standard remediation (credential rotation, wipes) often fails, provides indicators (files, artifacts, IPs), and gives a step-by-step, field-tested cleanup and mitigation checklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.