logo

ChainVeil and ViteVenom are DPRK’s PolinRider Campaign

ID: 68bbcd39-f200-5811-8ba2-268170ad7035

STIX ID: report--68bbcd39-f200-5811-8ba2-268170ad7035

Feed Name: OpenSourceMalware Blog

Threat Score
92/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

Author: cb482791-4ef1-4762-96ad-b0ca4bdd538e

...
...

### Executive summary OpenSourceMalware links Checkmarx's ChainVeil and ViteVenom supply-chain typosquatting campaigns to the DPRK-linked PolinRider (Lazarus) operation, citing byte-for-byte identical TRON/Aptos wallet addresses and XOR keys, a 77KB RAT, blockchain-based C2 across TRON/Aptos/Binance Smart Chain, and thousands of malicious assets and IOCs across npm, PyPI, Packagist and GitHub; the report recommends treating these as a single, actively managed APT supply-chain campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.