PolinRider is a DPRK-linked, Lazarus-aligned software supply-chain activity associated with the Contagious Interview campaign and with the evolution of TasksJacker tradecraft. Active since early 2026, it targets software developers, open-source maintainers, and cryptocurrency-sector personnel. Operators use recruiter and collaboration lures, malicious developer tooling, poisoned packages, compromised maintainer accounts, and infected developer workstations to gain access to source repositories and package-publishing ecosystems. PolinRider implants obfuscated JavaScript loaders into legitimate repositories and package artifacts, including developer configuration files and files disguised as benign assets. It abuses Visual Studio Code task execution on folder opening and build-time configuration execution to trigger payloads. The activity has affected GitHub repositories and package ecosystems including npm, Go modules, Composer packages, PyPI, and browser extensions. Compromised repositories are modified through automated propagation that reuses developers' authorized credentials to push malicious commits and publish trojanized releases. The malware chain employs multi-blockchain dead-drop infrastructure using TRON, Aptos, BNB Smart Chain, and Ethereum to resolve changing follow-on command-and-control locations and retrieve encrypted payloads. Identified follow-on malware includes BeaverTail, DEV#POPPER, InvisibleFerret, and OmniStealer. These payloads support remote command execution, credential theft, browser and cryptocurrency-wallet data theft, keylogging, clipboard collection, host reconnaissance, file upload, and persistent detached execution. PolinRider operators use extensive defense evasion, including code obfuscation, malicious code appended to otherwise functional projects and packages, whitespace concealment, CI-environment checks, spoofed or backdated commit metadata, Git-history rewriting, amended commits, and force-pushes. The activity is also assessed to overlap with or encompass campaigns referred to as ChainVeil and ViteVenom, based on shared blockchain-based payload-resolution tradecraft and campaign markers. PolinRider is associated with Contagious Interview, which is also tracked in parts of the security industry as Lazarus, Famous Chollima, STARDUST CHOLLIMA, or UNC1069 activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DPRK-linked activity cluster associated with a PyPI supply-chain attack; the post also tags OtterCandy in connection with the activity.
A DPRK-linked software supply-chain campaign that compromises legitimate GitHub developers and maintainers, persists via malicious VS Code tasks and trojanized config/files, and spreads malware into npm, Go, and PHP ecosystems through compromised maintainer accounts.
Referenced for tradecraft comparison; its behavior reportedly matched the appended-loader package hijacking pattern seen in the current npm package compromises.
Referenced as a DPRK-linked campaign previously observed using similar npm package hijacking behavior with malicious loader code appended to legitimate files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.