PolinRider is a North Korea-linked software supply chain intrusion cluster associated with the Lazarus ecosystem and closely tied to the broader Contagious Interview activity. The campaign emerged in early 2026 and targets software developers, open-source maintainers, and cryptocurrency-focused organizations by compromising developer workstations and maintainer accounts, then abusing trusted software distribution channels and source repositories to propagate malware. PolinRider has been linked to malicious activity across GitHub repositories, npm, Go modules, Packagist, PyPI, and browser-extension ecosystems. Reported operations include widespread repository tampering, malicious pull requests, package hijacking, typosquatted package publication, and upstream injection using credentials stolen from infected developers. The cluster is also described as overlapping with or incorporating earlier activity tracked as TasksJacker, and as related to Contagious Interview aliases including Lazarus, Famous Chollima, STARDUST CHOLLIMA, and UNC1069. A defining characteristic of PolinRider is developer-focused initial access. Operators use fake recruiter and interview lures, poisoned repositories, malicious Visual Studio Code task files, compromised extensions, and trojanized packages to infect developer environments. Once on a system, the malware steals credentials and tokens, including Git and package-publishing access, then uses the victim's own authorized context to clone repositories, append malicious code to legitimate project files, publish infected package versions, and conceal tampering through Git history rewriting and timestamp manipulation. The campaign has repeatedly abused developer tooling and build workflows for execution and persistence. Observed techniques include malicious VS Code tasks configured to run when a folder is opened, code appended to common JavaScript configuration files, build-time execution through project configuration modules, and detached background processes that survive beyond the original development task. PolinRider malware has also been observed modifying repositories at scale and using automation artifacts associated with force-push and commit-rewrite workflows. PolinRider is notable for resilient blockchain-backed command-and-control and payload resolution. Multiple operations used TRON, Aptos, BNB Smart Chain, and in some cases Ethereum transaction data as dead-drop infrastructure to encode or relay follow-on payload locations and commands. Loaders query public blockchain infrastructure, decode encrypted second-stage data, and execute additional JavaScript or child processes. This design reduces dependence on static infrastructure and enables rapid payload rotation without republishing packages. Associated malware and payloads include BeaverTail, DEV#POPPER, OmniStealer, and InvisibleFerret. Reported capabilities include credential theft, browser and wallet data theft, keylogging, clipboard theft, remote command execution, file upload, persistence, and broader post-compromise malware staging. The campaign has specifically targeted secrets useful for software supply chain compromise, including Git credentials, npm publishing tokens, SSH material, cloud and CI/CD secrets, browser-stored credentials, and cryptocurrency-wallet data. Victimology centers on software developers and the cryptocurrency ecosystem. PolinRider has been observed implanting malware into hundreds to thousands of public repositories and publishing large numbers of malicious packages and extensions. The operation appears designed both to steal credentials and cryptocurrency-related data and to weaponize compromised developer trust relationships for downstream supply chain compromise. The dominant motivation is best assessed as espionage-aligned state activity with strong overlap into cryptocurrency theft and strategic access operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for tradecraft comparison; its behavior reportedly matched the appended-loader package hijacking pattern seen in the current npm package compromises.
Referenced as a DPRK-linked campaign previously observed using similar npm package hijacking behavior with malicious loader code appended to legitimate files.
Referenced as a DPRK-linked campaign exhibiting similar package-hijacking behavior with malicious loader code appended to legitimate files.
A DPRK-linked supply-chain campaign compromising developer machines and accounts to silently propagate malicious code into GitHub repositories, Go modules, npm packages, and Packagist packages using poisoned repos, typosquatted packages, fake interviews, malicious VS Code tasks, credential theft, and automated publishing/commit abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.