A Developer's Guide to Getting Rid of PolinRider
ID: 315f8066-6906-55dd-bea5-9e3e94c209bd
STIX ID: report--315f8066-6906-55dd-bea5-9e3e94c209bd
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-13
Date Updated: 2026-08-13
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
PolinRider is a DPRK-run malware campaign targeting individual software developers via booby-trapped VS Code tasks, typosquatted/npm trojan packages, and infected forks/PRs; it steals credentials (browser, SSH, cloud, registry tokens, etc.), self-propagates across repos and registries using victim credentials, and persists via local propagation scripts and blockchain-based C2. The post details infection vectors, why standard remediation (credential rotation, wipes) often fails, provides indicators (files, artifacts, IPs), and gives a step-by-step, field-tested cleanup and mitigation checklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
