logo

Hundreds of GitHub Repos Compromised By DPRK's PolinRider Campaign

ID: d3c7825a-6c12-59a1-a5b9-dc8df898b6a6

STIX ID: report--d3c7825a-6c12-59a1-a5b9-dc8df898b6a6

Feed Name: OpenSourceMalware Blog

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-08-06

Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2

...
...

OpenSourceMalware attributes a large supply-chain campaign called PolinRider to DPRK-linked Lazarus actors that has injected heavily obfuscated JavaScript into 675 public GitHub repositories across 352 owners; the initial vector appears to be malicious npm packages or a VS Code extension. The multi-stage payload functions as an infostealer/backdoor that appends to common JS config files, uses blockchain transactions (TRON/Aptos/BSC) as immutable dead-drop C2 with XOR-encrypted payloads executed via eval(), and includes Windows batch tooling that rewrites git commits to hide modifications; the report includes IOCs, affected repository lists, YARA rules, and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.