PolinRider is a staged JavaScript and Node.js loader family associated with a DPRK-linked software supply-chain campaign targeting software developers, development workstations, and CI environments. It operates on Windows, macOS, and Linux and spreads through compromised GitHub repositories and accounts, malicious pull requests, and contaminated packages distributed through npm, Packagist, and crates.io. Execution is triggered by automatic Visual Studio Code folder-opening tasks or malicious code embedded in project configuration loaded during builds, linting, testing, and other development workflows. Payloads are concealed using obfuscation, whitespace padding, and JavaScript masquerading as font assets.
PolinRider uses blockchain transactions, including Ethereum transactions, as dead-drop resolvers for command-and-control configuration. Loaders decode server addresses from transaction data and retrieve additional JavaScript and Python stages. Detached processes allow execution to continue after the initiating editor or development command exits. Its payload chain includes remote-control functionality, operator-supplied code execution, and credential-stealing components. Collection targets include environment secrets, browser passwords and cookies, Git and developer-tool credentials, password-manager data, cryptocurrency-wallet files and extension storage, and operating-system credential stores accessible to the compromised user. Collected data is packaged and exfiltrated to command-and-control infrastructure, with Telegram document uploads available as a fallback.
Infected developer systems can automatically inject malicious code into accessible local repositories, rewrite commits, and force-push altered history using legitimate contributor access. The malware preserves or manipulates commit identities, messages, and timestamps to conceal tampering. This propagation can affect multiple repositories and branches and reintroduce payloads after repository-only cleanup. Additional components modify application scripts to enable reinfection. Output suppression, environment checks for analysis and CI systems, dynamic execution, and deletion of uploaded collection archives further reduce visibility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“PolinRider malware (DPRK-attributed, Lazarus/Contagious Interview cluster) has been detected in two independent open pull requests against this repository.”
“PolinRider malware (DPRK-attributed, Lazarus/Contagious Interview cluster) has been detected in two independent open pull requests against this repository.”
PolinRider is supply-chain campaign that hides obfuscated JavaScript inside compromised developers' .vscode/tasks.json files, fake .woff2 fonts, and legitimate config files like tailwind.config.js, postcss.config.mjs, eslint.config.mjs, App.js and babel.config.cjs.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
GitHub’s log records which account’s credentials made a push ... 19 accounts force-pushed over eight months, and 18 of them show the same commit-rewriting pattern.
“The operators compromise developer accounts, insert malicious content into source repositories” and malicious changes were introduced through the compromised “LaHiRu” developer account.
"PolinRider Spreads Through Compromised GitHub Accounts and Packagist"
« ciblant des développeurs via des dépôts GitHub infectés » ; l’organisation GitHub Binary-Mindz et ses dépôts TypeScript ont été infectés.
Once a developer’s machine is infected, the malware running on their machine rewrites commits in every repo the developer has access to and force-pushes them. Any teammate who then opens one of those repos in VS Code gets infected too.
« .vscode/tasks.json : contient une tâche qui s’exécute automatiquement à l’ouverture du dossier et lance le payload » ; « Tâche curl dans tasks.json ».
GitHub’s log records which account’s credentials made a push ... 19 accounts force-pushed over eight months, and 18 of them show the same commit-rewriting pattern.
« .vscode/tasks.json : contient une tâche qui s’exécute automatiquement à l’ouverture du dossier et lance le payload » ; « Tâche curl dans tasks.json ».
GitHub’s log records which account’s credentials made a push ... 19 accounts force-pushed over eight months, and 18 of them show the same commit-rewriting pattern.
"The second edit puts the payload on the last line, after 2,000 space characters." TypeScript variants place the JavaScript in Base64 inside eval().
"The author field uses the name and email of an oxc maintainer" and "The attacker back-dates the commits in the same way as the oxc commit."
« fa-solid-900.woff2 : Nom de fichier Font Awesome légitime » ; les charges sont placées sous des chemins tels que public/fonts/fa-solid-*.woff2.
"On Linux, it reports Blocked (BOT) and deletes its work folder if the host has no saved passwords, no extensions, and no Firefox profile."
GitHub’s log records which account’s credentials made a push ... 19 accounts force-pushed over eight months, and 18 of them show the same commit-rewriting pattern.
“The operators compromise developer accounts, insert malicious content into source repositories” and malicious changes were introduced through the compromised “LaHiRu” developer account.
"It posts the complete process.env to /snv. On a developer computer, that includes cloud keys and registry tokens in the shell."
C2 paths ':443/0x/cls, :443/0x/ls'; response header 'X-Payload-B64'; request header 'Sec-V'.
"The loader encodes C2 IP addresses in the to field of Ethereum transactions."
159 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a hashtag accompanying a link about investigating GitHub repository history. The provided content does not describe its capabilities or involvement.
Compromises developer machines and propagates malicious code through their locally checked-out repositories. A Windows batch script, exemplified by temp_auto_push.bat, rolls back the system clock, substitutes Git identity metadata, amends existing commits with malicious changes, and force-pushes rewritten history to conceal the injection. In the nestjsx/nest-access-control case study, the malicious commit was actually force-pushed on September 8, 2026, despite retaining a December 24, 2025 timestamp. The injection included a hidden VS Code folder-open task that executes JavaScript disguised as public/fonts/fa-solid-500.woff2 using Node.js. The published npm package remained clean; exposure was confined to the poisoned GitHub repository rather than the published release. The source attributes the campaign broadly to DPRK but identifies no specific threat actor group and explicitly describes the implicated developer accounts as victims.
A named malware campaign/tool reported as switching its command-and-control (C2) mechanism to Ethereum across more than 30 repositories. The provided content does not specify its payload capabilities or malware category.
A multi-stage JavaScript/Node.js supply-chain loader injected into developer repositories and executed through build, test, bundler, and configuration scripts. It uses Ethereum transaction recipient addresses as a dead-drop resolver for rotating C2 infrastructure, launches detached Node.js processes, can bridge from WSL2 to Windows via node.exe, inventories and exfiltrates process environment secrets, installs Python tooling, and deploys a Python stealer targeting Chromium/Firefox credentials, Git credentials, browser cookies, and data from 153 browser extensions including cryptocurrency wallets and password managers. It can exfiltrate collected ZIP archives to its C2 or fall back to the Telegram Bot API.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.