PolinRider Jumps the Fence to Go, Packagist, npm, PyPI
ID: 826001cd-b8ca-5d1a-b00b-37c8960d092d
STIX ID: report--826001cd-b8ca-5d1a-b00b-37c8960d092d
Feed Name: OpenSourceMalware Blog
Date Published: 2026-07-08
Date Updated: 2026-08-06
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
PolinRider is a DPRK-linked supply-chain campaign that compromises GitHub accounts to append obfuscated JavaScript loaders into legitimate repositories, enabling automatic distribution into ecosystem models that resolve code from repos (notably Go modules and Packagist) and delivering a Lazarus stealer toolkit (Beavertail/InvisibleFerret/OmniStealer); the report includes IOCs (compromised repos, TRON/Aptos addresses, XOR keys, loader signatures), a timeline of expansion, and actionable remediation steps for maintainers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
