logo

NPM Isn't Prepared For North Korean PolinRider Attack

ID: ce2348fa-2ef4-5fe2-afe3-8a5c7e4e904e

STIX ID: report--ce2348fa-2ef4-5fe2-afe3-8a5c7e4e904e

Feed Name: OpenSourceMalware Blog

Threat Score
90/100

Date Published: 2026-08-25

Date Updated: 2026-08-24

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

OpenSourceMalware documents the PolinRider DPRK supply‑chain campaign that compromises individual GitHub developers and injects obfuscated JavaScript loaders into their repositories and npm packages; the case study focuses on DiogoAngelim's fetch-page-assets (multiple live malicious versions), provides timelines of account-wide force-pushes, concrete IOCs (package versions, commit SHAs, file hashes, Git blobs, Ethereum C2 wallet, RPC endpoints), and urges registry-level changes (maintainer-level advisories, direct notifications, pattern-based detection, cross-system correlation) to address the scale and persistence of the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.