SUBJECT PROFILE
Socket Threat Research Team disclosed on July 1–6, 2026 that the North Korea-linked PolinRider supply chain campaign has massively expanded across npm, Packagist, Go modules, and Chrome extensions, with 162 malicious artifacts identified across 108 unique packages. The campaign, attributed to the Famous Chollima / Contagious Interview cluster (Lazarus subset), compromises legitimate maintainer accounts and rewrites Git history to conceal injected obfuscated JavaScript loaders that deliver DEV#POPPER RAT and OmniStealer. As of July 7, 2026, the campaign remains fully active with new compromises continuously surfacing.
Revenue generation for DPRK weapons programs via developer credential and IP theft; strategic supply chain infiltration for downstream enterprise access
OPERATIONAL HISTORY
T1195.002 (Compromise Software Supply Chain via poisoned npm/PyPI/Go/Packagist/Chrome packages), T1059.007 (JavaScript obfuscated loaders hidden in config files / fake .woff2 fonts), T1027 (Obfuscation / whitespace-padding payload hiding), T1102 (Blockchain / RPC-based encrypted C2), T1078 (Compromised maintainer account takeover via expired domain hijacking), T1070.004 (Git history rewriting / anti-dated commits for anti-forensics), T1105 (Staged payload via VS Code auto-run tasks), T1056 (Credential Harvesting — Kubernetes tokens, cloud API keys, source code), T1547 (Boot/Logon persistence)
KNOWN INFRASTRUCTURE
Compromised GitHub repositories across multiple namespaces (e.g., Xpos587); malicious packages in npm, Packagist, Go modules, Chrome Web Store; second-stage payloads: DEV#POPPER RAT, OmniStealer infostealer; C2 via public blockchain / RPC endpoints for encryption key exchange; VS Code task-based auto-execution loaders; fake .woff2 font files and vite.config.js / eslint.config.js for payload concealment; live IOC tracker maintained at socket.dev/supply-chain-attacks/polinrider