DEV#POPPER is a cross-platform Node.js remote access trojan (RAT). In the reported activity, it was delivered as a second-stage payload in the North Korea-linked PolinRider software supply chain campaign, which is associated with the broader Contagious Interview / Famous Chollima (Void Dokkaebi) activity. The campaign has targeted open source software developers since at least December 2025 by compromising legitimate GitHub repositories, npm packages, Go modules, Packagist packages, and at least one Chrome extension. Infection vectors described in the content include obfuscated JavaScript loaders hidden in configuration files such as config.js and vite.config.js, fake .woff2 font files, and malicious .vscode/tasks.json files configured to run automatically when a folder is opened in Visual Studio Code.
The loaders contacted public blockchain RPC infrastructure on TRON, Aptos, BNB Smart Chain / Binance Smart Chain to retrieve encrypted payloads from blockchain transactions, decrypt them with an embedded XOR key, and execute them with eval. DEV#POPPER was one of the observed payloads delivered through this mechanism, alongside OmniStealer. The malware was described as capable of remote command execution and communication with attacker-controlled servers via socket.io-client. One analyzed DEV#POPPER variant carried version marker 260311 and supported multiple simultaneous operators through independent command queues. Reported network behavior included WebSocket-based C2 and HTTP endpoints '/verify-human/[VERSION]' for heartbeat/notification and '/u/f' for file uploads, directory exfiltration, and logging.
The content states DEV#POPPER can steal credentials, browser data, and cryptocurrency wallet information. It also reportedly avoids execution in CI/CD and sandbox environments, including GitLab CI and BuildBot, to focus on real developer workstations. Persistence behavior described for one variant included injecting versioned code marked C250617A through C250620A into developer applications such as Antigravity, VS Code, Cursor, Discord, and GitHub Desktop, and creating a hidden .node_modules folder to abuse Node.js module search order hijacking.
The malware is associated in the content with North Korean threat activity, including Famous Chollima / Void Dokkaebi and the broader Contagious Interview operation. The targeting emphasis is developer environments and software supply chains, with downstream risk to source code, cloud, package registry, wallet, browser, and CI/CD credentials. High-confidence indicators and artifacts mentioned in the content include use of socket.io-client for C2, the version marker 260311, the global['!'] loader marker seen in related repository infections, the HTTP paths '/verify-human/[VERSION]' and '/u/f', and blockchain-backed staging via TRON, Aptos, and BNB Smart Chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware, including a variant of the DEV#POPPER remote access trojan, retrieves encrypted payloads from blockchain transactions, decrypts them, and executes them on infected systems.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The compromised repositories contain obfuscated JavaScript loaders that connect to the blockchain and public remote procedure call (RPC) infrastructure to retrieve encrypted payloads.
The compromised repositories contain obfuscated JavaScript loaders that connect to the blockchain and public remote procedure call (RPC) infrastructure to retrieve encrypted payloads.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan delivered via compromised open source repositories and JavaScript loaders in the PolinRider supply chain campaign, used to backdoor developer environments.
A second-stage payload used in the PolinRider campaign that enables remote command execution and theft of credentials, browser data, and wallet information.
A remote access trojan deployed in a self-spreading supply chain intrusion campaign targeting developers through malicious GitHub or GitLab repositories and illicit Visual Studio Code task configurations.
A remote access trojan used in Void Dokkaebi's campaign that fetches encrypted payloads from blockchain transactions, decrypts them, and executes them on compromised developer systems, enabling dynamic payload updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.