A report from OpenSource Malware says the DPRK-linked PolinRider campaign compromised legitimate GitHub maintainer accounts and used them to publish malicious npm releases, highlighting a case involving developer DiogoAngelim and the packages fetch-page-assets and html-to-gutenberg. The report says fetch-page-assets version 1.2.9 was identified and removed under advisory GHSA-vxq2-vhm7-7mhq, but attackers continued publishing malicious versions 1.2.10 through 1.2.14, with payloads tied to PolinRider/NullReceiver concealed in files including .vscode/tasks.json, a fake .woff2 font, and later babel.config.cjs.
The article says the compromise extended beyond a single package: all seven non-archived public repositories under the maintainer’s account were allegedly reinfected in coordinated force-push waves, indicating sustained attacker control over both the GitHub account and build environment. OpenSource Malware estimates the campaign has reached 4,367 repositories across 2,152 owners and argues that current GitHub and npm response mechanisms, which focus on removing specific malicious versions, are insufficient when attackers retain control of trusted maintainer accounts and can repeatedly ship new poisoned releases.

Trace attribution and downstream blast radius.
11 events from the most recent confirmed update back to the earliest known activity.
A Bluesky account, lazarusholic, published a post on 2026-08-24 linking to the OpenSourceMalware article titled "NPM Isn't Prepared For North Korean PolinRider Attack." The post associated the case with GitHub, npm, PolinRider, and NullReceiver and characterized it as a North Korean attack.
The article says a raw-content check on 2026-08-24 returned HTTP 200 for .vscode/tasks.json on the main branch of all seven affected repositories. This was presented as confirmation that the malicious launcher remained present across the victim's public repos.
The report says fetch-page-assets versions 1.2.13 and 1.2.14 were published on 2026-08-23 and refreshed the babel.config.cjs payload. It identifies both versions with campaign marker global.i="A8-3292-2" and says v1.2.14 became the latest dist-tag on npm.
The article states the same seven DiogoAngelim repositories were reinfected in another coordinated force-push burst on 2026-08-23. GitHub timestamps reportedly showed the updates landed across all seven repositories within 30 seconds.
The report says commit 7bd8eb2 on 2026-07-31 restored the fake font payload and added a second obfuscated NullReceiver loader to babel.config.cjs in fetch-page-assets v1.2.12. It identifies this version with campaign marker global.i="A8-3292-1".
The article says all seven non-archived public repositories under DiogoAngelim were infected in a coordinated burst on 2026-07-31. GitHub server-side timestamps reportedly showed the seven repositories were updated within 56 seconds, indicating account-wide attacker control.
The report states npm pulled fetch-page-assets version 1.2.9 on 2026-06-24 after it was flagged. However, the article says later malicious versions remained available.
On 2026-06-24, GitHub Security Advisory GHSA-vxq2-vhm7-7mhq was published for fetch-page-assets. The advisory identified version 1.2.9 as malicious.
The article says JFrog published research in June about compromised npm packages fetch-page-assets v1.2.9 and html-to-gutenberg v4.2.11. This marked public reporting on the malicious package activity.
According to the report, fetch-page-assets version 1.2.9 was released on 2026-05-25 and was the first npm version to ship the malicious files to downstream users. The package carried the hidden VS Code task trigger and NullReceiver loader components.
The OpenSourceMalware case study says the initial compromise occurred on 2026-03-29 via a github-actions[bot] commit during a release workflow. It states the malicious changes added .vscode/tasks.json and a fake font file, public/fonts/fa-solid-400.woff2, to the repository.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.