PolinRider Caused Dozens of npm and Go Compromises
ID: 3bbff008-b345-51c3-9472-67062c56fab3
STIX ID: report--3bbff008-b345-51c3-9472-67062c56fab3
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-31
Date Updated: 2026-07-30
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
OpenSourceMalware attributes a set of compromises across npm and Go to DPRK’s PolinRider campaign: attackers used VS Code autorun tasks and a disguised JavaScript loader (fa-solid-400.woff2) that resolves XOR-encrypted payloads from blockchain RPCs (TRON, Aptos, BSC) to deliver RATs and infostealers; propagation occurs via a local propagation script (temp_auto_push.bat) that amends commits and forges commit timestamps, and npm publishes via harvested ~/.npmrc tokens — the report includes IOCs (XOR keys, TRON/Aptos wallets, C2 IPs and paths) and remediation guidance for maintainers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
