logo

PolinRider Confirmed Footprint Grows 6.5x Since March

ID: 9bdffd97-0778-5a36-a0d8-c46c16f1a7b5

STIX ID: report--9bdffd97-0778-5a36-a0d8-c46c16f1a7b5

Feed Name: OpenSourceMalware Blog

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

PolinRider is a large, active supply-chain campaign attributed to the Lazarus Group that has poisoned developer projects on GitHub by injecting obfuscated JavaScript into build/config files (postcss, tailwind, eslint, etc.) and smuggling code inside a .woff2 font; the July hunt found 2,417 newly-compromised repositories (4,367 cumulative across 2,152 owners), primarily individual developer accounts, and the report provides IOC markers, file targets, detection grep commands, and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.