PolinRider is a North Korea-linked software supply-chain threat cluster associated with the Contagious Interview campaign and Lazarus-aligned activity. Publicly identified in early 2026, it targets software developers and cryptocurrency-sector personnel through malicious developer tooling, poisoned repositories, compromised maintainer accounts, and infected package releases. Its operations have affected thousands of public repositories and span npm, Go, Packagist, PyPI, and browser extensions. Related npm activity includes the campaigns named ChainVeil and ViteVenom; PolinRider also overlaps with TasksJacker activity involving malicious editor tasks. The cluster conceals obfuscated JavaScript in legitimate project configuration files, appends loaders to otherwise functional packages, and disguises executable payloads as font resources. Execution can occur when packages are imported, projects are built, or repositories are opened in development environments through automatically triggered Visual Studio Code tasks. Infected developer systems provide access to Git and package-publishing credentials, enabling further repository modifications and malicious releases under legitimate maintainer identities. Git-history manipulation, forged timestamps, whitespace padding, and execution-environment checks help conceal malicious changes and evade analysis. PolinRider uses blockchain-based payload delivery and command-and-control discovery across TRON, Aptos, BNB Smart Chain, and Ethereum. Its NullReceiver technique derives command-and-control endpoints from Ethereum transaction recipient data, while other loaders use multichain relays to retrieve encrypted executable stages. Associated malware includes BeaverTail, DEV#POPPER, OmniStealer, and InvisibleFerret. These payloads support remote command execution, credential and browser-data theft, cryptocurrency-wallet data theft, clipboard collection, keylogging, file exfiltration, and persistence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly poisons Nova and uses on-chain transactions as a command-and-control manager.
Reportedly compromised/poisoned Nova and used blockchain-based transactions as a command-and-control manager.
A DPRK-linked software-supply-chain campaign targeting developer repositories. It is associated with silently appending payloads to legitimate project configuration files, harvesting cached Git credentials from infected developer systems, using those credentials to push malicious code, and retrieving command-and-control configuration from Ethereum blockchain transactions.
Named activity cluster mentioned as a tradecraft comparison: WeaselBiscuit's numeric installation identifiers resemble its campaign-marker convention. The report does not establish shared operators or a direct operational connection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.