North Korea-linked PolinRider campaign hijacks more than 100 open-source packages and repositories to backdoor developers

North Korean hackers are compromising legitimate open-source packages and code repositories to infect software developers with a backdoor and an information stealer. Socket says the PolinRider campaign has been active since December 2025 and has produced 162 malicious release artifacts across 108 packages spanning npm, Packagist, Go modules, and Chrome extensions. The attackers reportedly hijack maintainer accounts, rewrite Git history to hide tampering, and use obfuscated JavaScript loaders to fetch DEV#POPPER remote-access malware and OmniStealer via blockchain and public remote procedure call infrastructure.
Why it matters: This can put developer laptops, source code, cloud accounts, and continuous integration and delivery secrets at risk even when teams install what look like trusted updates. Organizations that installed affected package or extension versions should treat those systems as compromised, investigate from clean machines, and rotate exposed credentials.

Sources

North Korean Hackers Target Open Source Developers in Supply Chain Attacks
Ionut Arghire 2026.07.06 100% relevant
This article establishes a distinct, named campaign—PolinRider—with its own scope, tactics, malware families, and package ecosystem impact, rather than merely updating a previously tracked single-package or single-namespace compromise.
← Back to all stories