AUTO-UPDATED

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

North Korean threat actors are actively compromising software supply chains through the PolinRider campaign, which uses malicious packages and VS Code tasks to distribute malware to unsuspecting developers.

Key Points

  • The PolinRider campaign has deployed 108 unique malicious packages and extensions across npm, Packagist, Go, and Google Chrome.
  • Attackers have compromised 1,951 public GitHub repositories by exploiting maintainer accounts and injecting obfuscated JavaScript loaders.
  • Malicious VS Code task files are used to trigger arbitrary code execution when developers open infected folders in IDEs like VS Code or Cursor.
  • The campaign delivers second-stage payloads, including the DEV#POPPER RAT and OmniStealer, by fetching encrypted data from blockchain infrastructure.
  • Threat actors use Git history rewriting and anti-dated commits to disguise malicious changes as legitimate, long-standing repository updates.

Why it Matters

This campaign highlights a significant escalation in supply chain attacks that target developer environments rather than just end-user applications. By compromising trusted repositories and IDE configurations, these actors can bypass traditional security measures and gain persistent access to sensitive development infrastructure.
Internet Published by info@thehackernews.com (The Hacker News)
Read original