NPM Isn't Prepared For North Korean PolinRider Attack
ID: ce2348fa-2ef4-5fe2-afe3-8a5c7e4e904e
STIX ID: report--ce2348fa-2ef4-5fe2-afe3-8a5c7e4e904e
Feed Name: OpenSourceMalware Blog
Date Published: 2026-08-25
Date Updated: 2026-08-24
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
OpenSourceMalware documents the PolinRider DPRK supply‑chain campaign that compromises individual GitHub developers and injects obfuscated JavaScript loaders into their repositories and npm packages; the case study focuses on DiogoAngelim's fetch-page-assets (multiple live malicious versions), provides timelines of account-wide force-pushes, concrete IOCs (package versions, commit SHAs, file hashes, Git blobs, Ethereum C2 wallet, RPC endpoints), and urges registry-level changes (maintainer-level advisories, direct notifications, pattern-based detection, cross-system correlation) to address the scale and persistence of the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
