logo

PolinRider Jumps the Fence to Go, Packagist, npm, PyPI

ID: 826001cd-b8ca-5d1a-b00b-37c8960d092d

STIX ID: report--826001cd-b8ca-5d1a-b00b-37c8960d092d

Feed Name: OpenSourceMalware Blog

Threat Score
90/100

Date Published: 2026-07-08

Date Updated: 2026-08-06

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

PolinRider is a DPRK-linked supply-chain campaign that compromises GitHub accounts to append obfuscated JavaScript loaders into legitimate repositories, enabling automatic distribution into ecosystem models that resolve code from repos (notably Go modules and Packagist) and delivering a Lazarus stealer toolkit (Beavertail/InvisibleFerret/OmniStealer); the report includes IOCs (compromised repos, TRON/Aptos addresses, XOR keys, loader signatures), a timeline of expansion, and actionable remediation steps for maintainers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.