Hundreds of GitHub Repos Compromised By DPRK's PolinRider Campaign
ID: d3c7825a-6c12-59a1-a5b9-dc8df898b6a6
STIX ID: report--d3c7825a-6c12-59a1-a5b9-dc8df898b6a6
Feed Name: OpenSourceMalware Blog
Date Published: 2026-04-08
Date Updated: 2026-08-06
Author: c0a15726-c5b1-4b0d-85e6-fe15553df9e2
OpenSourceMalware attributes a large supply-chain campaign called PolinRider to DPRK-linked Lazarus actors that has injected heavily obfuscated JavaScript into 675 public GitHub repositories across 352 owners; the initial vector appears to be malicious npm packages or a VS Code extension. The multi-stage payload functions as an infostealer/backdoor that appends to common JS config files, uses blockchain transactions (TRON/Aptos/BSC) as immutable dead-drop C2 with XOR-encrypted payloads executed via eval(), and includes Windows batch tooling that rewrites git commits to hide modifications; the report includes IOCs, affected repository lists, YARA rules, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
