VMTech
Discuss a project

Heads up: North Korean hackers and 108 malicious packages in PolinRider

Heads up: North Korean hackers and 108 malicious packages in PolinRider

Colleagues, I’d like to draw your attention to a cybersecurity story.

The PolinRider campaign involved North Korean threat actors behind 108 malicious packages and extensions across npm, Packagist, Go, and Chrome.

What stands out:
• the attack is disguised as developer hiring and interview processes;
• attackers use GitHub, VS Code task files, and commit history tampering;
• once executed, the malware searches for config files and implants itself;
• the end goal is malware delivery and data theft.

Why it matters: these supply chain chains can quietly impact entire teams and repositories.

If you work with open source packages, do you verify their provenance and change history?

#cybersecurity #supplychain #GitHub #malware

Open analytics
On the site 0 views
min read 1 04.07.2026
Instagram

Heads up: North Korean hackers and 108 malicious packages in PolinRider

Open the post on Instagram ↗