PolinRider is a DPRK-linked, Lazarus-aligned software supply chain threat activity associated with the broader Contagious Interview campaign and overlaps with the TasksJacker cluster. It targets software developers and individuals in the cryptocurrency sector through malicious open-source packages, browser extensions, compromised maintainer and developer accounts, tampered GitHub repositories, and malicious pull requests. The activity has been described as linked to North Korean actors including Lazarus, Famous Chollima, STARDUST CHOLLIMA, and UNC1069. Reported activity includes publication of 108 malicious packages and browser extensions spanning npm, Packagist, Go, and the Chrome Web Store, producing 162 malicious release artifacts. Researchers also reported widespread compromise of public GitHub repositories, with hundreds to nearly 2,000 repositories and more than 1,000 owners affected in 2026 reporting. PolinRider has been linked to account hijacking on platforms such as GitHub, Visual Studio Code, and npm, including compromise via expired domain takeover or account recovery paths, as well as malicious VS Code extensions or npm packages. Tradecraft described in the content includes social engineering through fake recruiter or collaborator personas tied to Contagious Interview; insertion of obfuscated JavaScript loaders into legitimate repositories and configuration files; abuse of VS Code .vscode/tasks.json with "runOn": "folderOpen" for code execution; stealthy modification of files such as postcss, Tailwind, ESLint, Next.js, Babel, app.js, and astro.config.mjs; and Git history rewriting to conceal malicious changes by spoofing commit metadata and overwriting timestamps and messages. The malware has been reported to hide payloads with whitespace padding or fake .woff2 font files and to repeatedly push malicious updates after repository access is obtained. The malware chain is linked to BeaverTail variants that search project directories for common JavaScript configuration files and append malicious code. Recent variants retrieve encrypted second-stage payloads from blockchain infrastructure including TRON, Aptos, and BNB Smart Chain, then decrypt and execute follow-on payloads including DEV#POPPER RAT and OmniStealer. A documented malicious pull request case targeting astro.config.mjs was attributed to PolinRider based on matching decoder logic, XOR keys, blockchain dead-drop infrastructure, globals, and propagation artifacts. The content also states that TasksJacker evolved into PolinRider, with PolinRider using stolen credentials to fork popular projects, inject malicious JavaScript configuration files, and submit malicious pull requests upstream. Known related names and overlaps directly mentioned in the content include Contagious Interview, TasksJacker, Lazarus, Famous Chollima, STARDUST CHOLLIMA, and UNC1069.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a software supply chain campaign targeting developers and cryptocurrency-focused users by compromising developer accounts, publishing malicious packages and browser extensions, and deploying BeaverTail followed by DEV#POPPER RAT and OmniStealer.
Ongoing activity associated with Contagious Interview involving malicious packages, compromised repositories, obfuscated JavaScript payloads, and delivery of BeaverTail and later-stage malware.
Discussed in connection with an astro.config.mjs supply chain attack using blockchain C2.
Associated with the Contagious Interview campaign targeting developers through recruiter-themed social engineering and malicious repositories.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.