North Korean Hackers Poison Open Source Packages in Ongoing Supply Chain Attack
Want more insights like this?
Researchers at Socket have tracked a North Korea-linked campaign quietly compromising open source software since December 2025, which they've named PolinRider. It sits under the broader Contagious Interview operation.
The attackers hijack legitimate GitHub maintainer accounts, inject obfuscated JavaScript loaders into real repositories, and use Git history rewriting to make the changes look old. The loaders pull encrypted payloads from blockchain and public RPC infrastructure, which makes the delivery channel hard to take down. Two payloads follow: the DEV#POPPER RAT and OmniStealer.
So far, 162 malicious artifacts across 108 packages have been found on NPM, Packagist, Go modules and Chrome extensions. Any developer who installed an affected package should assume their environment is compromised — and because credentials may already be exposed, remediate from a clean machine rather than the infected host.
Source: SecurityWeek