PolinRider is a DPRK-linked software supply-chain threat cluster associated with the Lazarus ecosystem and closely tied to the broader Contagious Interview activity. The operation targets software developers, open-source maintainers, and cryptocurrency-focused users by compromising developer accounts and workstations, tampering with legitimate repositories, and publishing trojanized packages and extensions across ecosystems including npm, Go modules, Packagist, and browser extension platforms. Reporting also links PolinRider to the evolution and convergence of earlier developer-focused clusters such as TasksJacker, and some tracking overlaps with aliases and related designations including Lazarus, Famous Chollima, STARDUST CHOLLIMA, and UNC1069. The actor’s tradecraft centers on abusing trusted developer workflows rather than relying solely on overtly malicious packages. Observed techniques include insertion of obfuscated JavaScript into legitimate configuration and application files, malicious Visual Studio Code task files configured to execute when a repository is opened, package hijacking through compromised maintainer credentials, malicious pull requests targeting build pipelines, and Git history manipulation to conceal unauthorized changes. PolinRider has repeatedly appended malicious loaders to otherwise functional package files, preserving expected behavior to reduce suspicion. The actor has also used fake font files and legitimate-looking config files as execution surfaces, and has been observed modifying commit metadata and force-pushing rewritten history across multiple repositories in coordinated bursts. A distinctive feature of PolinRider is resilient blockchain-assisted payload resolution and command retrieval. Multiple campaigns attributed to the cluster used dead-drop style retrieval through public blockchain infrastructure, including TRON, Aptos, BNB Smart Chain, and in some cases Ethereum-based NullReceiver-style resolution. These loaders recover encrypted follow-on payloads or command data from blockchain-linked transactions, then decode and execute additional stages in-process or as detached child processes. This design complicates takedown efforts and allows operators to rotate payloads without republishing every malicious package. Follow-on malware associated with PolinRider includes BeaverTail, DEV#POPPER, OmniStealer, InvisibleFerret, and NullReceiver-related loaders. Observed post-compromise behavior includes credential theft, browser and wallet data theft, keylogging, exfiltration, persistence through background processes or developer-tooling triggers, and remote access capabilities. Stolen credentials have reportedly been reused to clone repositories, push backdoored commits, publish malicious releases, and propagate compromise across additional developer-owned assets. The actor has also shown defense-evasion behavior through CI-environment checks, obfuscation, timestamp forgery, and concealment inside legitimate source trees. Victimology is concentrated on software developers, open-source maintainers, and organizations connected to cryptocurrency development and operations. Public reporting describes widespread compromise of GitHub repositories and package ecosystems, including large-scale infection of public repositories under legitimate owners and repeated reinfection of compromised maintainer projects. The campaign reflects a sustained espionage-linked North Korean effort that also monetizes access through theft of credentials and cryptocurrency-related data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DPRK-linked software supply-chain campaign that compromises legitimate GitHub developers and maintainers, persists via malicious VS Code tasks and trojanized config/files, and spreads malware into npm, Go, and PHP ecosystems through compromised maintainer accounts.
Referenced for tradecraft comparison; its behavior reportedly matched the appended-loader package hijacking pattern seen in the current npm package compromises.
Referenced as a DPRK-linked campaign previously observed using similar npm package hijacking behavior with malicious loader code appended to legitimate files.
Referenced as a DPRK-linked campaign exhibiting similar package-hijacking behavior with malicious loader code appended to legitimate files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.