North Korean threat actors are actively compromising software supply chains through the PolinRider campaign, which uses malicious packages and VS Code tasks to distribute malware to unsuspecting developers.
Key Points
- The PolinRider campaign has deployed 108 unique malicious packages and extensions across npm, Packagist, Go, and Google Chrome.
- Attackers have compromised 1,951 public GitHub repositories by exploiting maintainer accounts and injecting obfuscated JavaScript loaders.
- Malicious VS Code task files are used to trigger arbitrary code execution when developers open infected folders in IDEs like VS Code or Cursor.
- The campaign delivers second-stage payloads, including the DEV#POPPER RAT and OmniStealer, by fetching encrypted data from blockchain infrastructure.
- Threat actors use Git history rewriting and anti-dated commits to disguise malicious changes as legitimate, long-standing repository updates.