North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
Lazarus-linked actors scaled the PolinRider campaign to 108 malicious packages across npm, Packagist, Go, and Chrome extensions — a multi-ecosystem poisoning effort that dramatically widens developer supply-chain exposure.
Summary written by editorial AI · Source link below
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.
"The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer accounts,
Editorial Analysis
The multi-ecosystem scope signals that state-sponsored supply-chain attacks are no longer confined to npm alone; any developer toolchain is a viable vector.
Enforce package provenance checks and allowlisting across all language ecosystems in your CI/CD pipelines, not just npm.
North Korean threat actors are poisoning developer package registries at industrial scale, threatening any organisation that builds software.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul