DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // POLINRIDER-FAMOUS-CHOLLIMAFIRST SEEN: DEC 2025

POLINRIDER (Famous Chollima)

ALSO KNOWN AS: Contagious Interview, Famous Chollima, Lazarus Group (subset), DEV#POPPER operators
FROM:DMZ INTELLIGENCE DESK
ORIGIN:North Korea (DPRK)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:DEC 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL85/100
RESOURCES93/100
PERSISTENCE93/100
STEALTH93/100
IMPACT85/100

Socket Threat Research Team disclosed on July 1–6, 2026 that the North Korea-linked PolinRider supply chain campaign has massively expanded across npm, Packagist, Go modules, and Chrome extensions, with 162 malicious artifacts identified across 108 unique packages. The campaign, attributed to the Famous Chollima / Contagious Interview cluster (Lazarus subset), compromises legitimate maintainer accounts and rewrites Git history to conceal injected obfuscated JavaScript loaders that deliver DEV#POPPER RAT and OmniStealer. As of July 7, 2026, the campaign remains fully active with new compromises continuously surfacing.

Revenue generation for DPRK weapons programs via developer credential and IP theft; strategic supply chain infiltration for downstream enterprise access

T1195.002 (Compromise Software Supply Chain via poisoned npm/PyPI/Go/Packagist/Chrome packages), T1059.007 (JavaScript obfuscated loaders hidden in config files / fake .woff2 fonts), T1027 (Obfuscation / whitespace-padding payload hiding), T1102 (Blockchain / RPC-based encrypted C2), T1078 (Compromised maintainer account takeover via expired domain hijacking), T1070.004 (Git history rewriting / anti-dated commits for anti-forensics), T1105 (Staged payload via VS Code auto-run tasks), T1056 (Credential Harvesting — Kubernetes tokens, cloud API keys, source code), T1547 (Boot/Logon persistence)

SOFTWARE DEVELOPERS
OPEN SOURCE MAINTAINERS
TECHNOLOGY / CLOUD
FINANCIAL SERVICES
CRYPTOCURRENCY

Compromised GitHub repositories across multiple namespaces (e.g., Xpos587); malicious packages in npm, Packagist, Go modules, Chrome Web Store; second-stage payloads: DEV#POPPER RAT, OmniStealer infostealer; C2 via public blockchain / RPC endpoints for encryption key exchange; VS Code task-based auto-execution loaders; fake .woff2 font files and vite.config.js / eslint.config.js for payload concealment; live IOC tracker maintained at socket.dev/supply-chain-attacks/polinrider

FILE DATE: DEC 2025
PolinRider Phase 1 — npm Initial Compromise
Campaign launched targeting npm registry; implanted obfuscated JavaScript loaders in packages to deliver DEV#POPPER RAT and OmniStealer to developer environments.
FILE DATE: JUL 2026
PolinRider Phase 2 — Multi-Ecosystem Expansion (ACTIVE)
Active expansion to Packagist, Go modules, and Chrome extensions; 162 malicious ████████████████████ packages confirmed as of July 6, 2026; compromised maintainer accounts used to push tainted updates into enterprise CI/CD pipelines; campaign ongoing.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn