PolinRider is a North Korea-aligned software supply chain threat cluster assessed to be associated with Lazarus Group activity and closely related to, or a sub-campaign within, Contagious Interview. The operation emerged in early 2026 and appears to build on earlier developer-focused intrusion activity linked to TasksJacker, including the reuse of stolen developer credentials, compromised maintainer accounts, malicious Visual Studio Code task execution, and upstream pull-request injection. Known aliases and overlapping tracking names in reporting include Lazarus, Famous Chollima, STARDUST CHOLLIMA, UNC1069, and Contagious Interview-related clusters. PolinRider primarily targets software developers and cryptocurrency-sector personnel. Victimization has included compromised GitHub repository owners, npm and Visual Studio Code accounts, and maintainers of open-source packages and extensions. The cluster has been observed distributing malicious artifacts across multiple developer ecosystems, including npm, Packagist, Go modules, and browser extensions, while also implanting obfuscated JavaScript into large numbers of public GitHub repositories and tampering with legitimate repositories after account takeover. The actor’s tradecraft centers on supply chain compromise, social engineering, and developer-workflow abuse. Initial access has been associated with recruiter-style lures characteristic of Contagious Interview, as well as account takeover through maintainer-account compromise and account recovery or domain-takeover paths. Post-compromise activity includes publishing trojanized package versions, modifying repository contents, submitting malicious pull requests, and planting execution triggers in developer tooling such as Visual Studio Code tasks configured to run when a folder is opened. PolinRider has also hidden malicious code in JavaScript configuration files and other trusted project components so that execution occurs during normal build, development, or preview workflows rather than through obvious package-install hooks. A defining feature of PolinRider is resilient blockchain-backed command-and-control. The cluster has repeatedly used a multi-stage resolver spanning TRON, Aptos, and BNB Smart Chain to retrieve encrypted second-stage payloads and update them without republishing malicious packages. This infrastructure pattern has been linked across PolinRider, TasksJacker, ChainVeil, and ViteVenom activity, supporting assessment that these are parts of the same broader DPRK-linked operation. Malware associated with PolinRider includes BeaverTail, DEV#POPPER, and OmniStealer. BeaverTail has been used to search project directories for common JavaScript configuration files and append malicious code to them. DEV#POPPER functions as a remote access trojan capable of command execution, file upload, host reconnaissance, and retrieval of additional JavaScript payloads. OmniStealer has been used for credential and data theft, including browser data, wallet-related extension storage, Git credentials, developer-tool configuration, and other sensitive host information. The cluster has also demonstrated clipboard theft and persistence beyond the original Node.js process. Defense evasion is a notable aspect of the operation. PolinRider has concealed implants with obfuscation, whitespace padding, and disguised content, and has rewritten Git history by altering commit metadata, timestamps, and messages to make malicious changes appear legitimate. The actor has also used detached processes and layered payload delivery to survive beyond the initial developer action that triggered execution. PolinRider is best characterized as an espionage-motivated DPRK supply chain actor with strong overlap with cryptocurrency-focused theft operations. Its campaigns show sustained interest in compromising trusted developer workflows, harvesting credentials and wallet data, and leveraging access to propagate malicious code through upstream software ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster linked to the multi-blockchain resolver structure used in the malicious npm packages.
Software supply chain campaign spanning GitHub, Go, Packagist, npm, and PyPI, using blockchain-based command infrastructure and tied by the article to ChainVeil and ViteVenom as the same operator/campaign.
Conducting a software supply chain campaign targeting developers and cryptocurrency-focused users by compromising developer accounts, publishing malicious packages and browser extensions, and deploying BeaverTail followed by DEV#POPPER RAT and OmniStealer.
Ongoing activity associated with Contagious Interview involving malicious packages, compromised repositories, obfuscated JavaScript payloads, and delivery of BeaverTail and later-stage malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.