ChainVeil and ViteVenom are DPRK’s PolinRider Campaign
ID: 68bbcd39-f200-5811-8ba2-268170ad7035
STIX ID: report--68bbcd39-f200-5811-8ba2-268170ad7035
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-17
Date Updated: 2026-07-18
Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e
### Executive summary OpenSourceMalware links Checkmarx's ChainVeil and ViteVenom supply-chain typosquatting campaigns to the DPRK-linked PolinRider (Lazarus) operation, citing byte-for-byte identical TRON/Aptos wallet addresses and XOR keys, a 77KB RAT, blockchain-based C2 across TRON/Aptos/Binance Smart Chain, and thousands of malicious assets and IOCs across npm, PyPI, Packagist and GitHub; the report recommends treating these as a single, actively managed APT supply-chain campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
