← Back to Daily Briefing

North Korean state-sponsored actors, associated with the PolinRider operation and Contagious Interview campaign, are executing a multi-vector supply chain offensive targeting the developer ecosystem. By compromising GitHub maintainer accounts and utilizing package impersonation, the actors injected malicious code into npm, Packagist, and Go ecosystems. The campaign specifically targets modern toolchains, including Claude Code and GitHub CLI, to deploy Windows Remote Access Trojans (RATs), Linux native C rootkits, and credential stealers aimed at SSH keys and developer tokens. With over 108 unique malicious packages and extensions identified, the operation seeks persistent high-level access to DevOps environments and AI-assisted coding workflows.

  • Incident Overview: Operation PolinRider

    • Attributed to North Korean state-sponsored threat actors linked to the "Contagious Interview" campaign.
    • Identified 108 unique malicious packages and browser extensions distributed across multiple registries.
    • Operation remains active, with threat actors continuously hijacking maintainer accounts to release infected versions.
  • Attack Vectors & Delivery Mechanics

    • Account Hijacking: Compromising legitimate GitHub maintainer accounts to publish malicious updates to trusted packages.
    • Ecosystem Poisoning: Utilizing impersonation and typosquatting across npm, Packagist, and Go package managers.
    • Browser-Based Vectors: Deployment of malicious Google Chrome extensions to facilitate initial access and data theft.
  • Technical Payload Analysis

    • Windows RAT: High-level Remote Access Trojans used for command execution and system control.
    • Linux C Rootkit: Deployment of native C-based rootkits to ensure stealthy, low-level persistence on developer machines.
    • Credential Exfiltration: Specialized stealers designed to target SSH keys and developer-specific authentication tokens.
  • Targeted Toolchains & Impact

    • AI-Assisted Coding: Specifically targeting Claude Code to intercept sensitive prompts, API keys, or source code.
    • CLI Tooling: Targeting GitHub CLI to gain unauthorized access to private repositories and CI/CD pipelines.
    • Demographic Focus: High-value targets include software developers, DevOps engineers, and AI practitioners.
  • Defensive Actions & Mitigation

    • Implement strict dependency pinning and utilize lockfiles (e.g., package-lock.json) to prevent automatic updates to compromised versions.
    • Mandate hardware-based MFA for all maintainer accounts and developer identities.
    • Conduct audits of installed browser extensions and monitor for anomalous outbound traffic to unknown C2 infrastructure.

Related posts

  1. techjacksolutions.com — Concurrent npm Supply Chain Campaigns Deliver Windows RAT, Linux Rootkit, and Developer Credential Stealers, One Cluster Linked to North Korean PolinRider Operation
  2. feeds.feedburner.com — North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
  3. threat-modeling.com — North Korean PolinRider Campaign: 108 Malicious Packages Across npm, Packagist, Go, and Chrome — Active Supply Chain Attack
  4. gbhackers.com — Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
  5. Google Cloud Security Community — Beyond Chat: Building an Autonomous SOC Analyst with Claude and the Google MCP
  6. feeds.feedburner.com — Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
  7. malware-log.hatenablog.com — North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections
  8. gbhackers.com — North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
  9. xploitzone.com — DPRK Fake IT Workers Exposed Stealer Logs Reveal North Korea Network Infrastructure
  10. cybersecurity.pk — FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
  11. gbhackers.com — AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
  12. cyberscoop.com — North Korea’s IT worker scheme funds Russia’s war effort
  13. SC Media — North Korea's IT worker scheme funds Russia's war effort, report finds
  14. threatlabsnews.xcitium.com — FakeGit Exposed: How 7,600 GitHub Repos Are Spreading SmartLoader Malware
  15. arXiv (Computer Science - Cryptography and Security) — ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems
  16. Malware News — Amazon uncovers broad North Korean hacking campaign against open-source software
  17. serisec.com — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
  18. The Record by Recorded Future — North Korean hackers behind major open-source supply chain attacks, Amazon says
  19. falconinternet.net — One Phished Maintainer, Four Poisoned Packages: Amazon Names North Korea in npm Supply Chain Campaign
  20. DEV Community — Stop Leaking Secrets into your LLM Context Windows
  21. eSecurity Planet — Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
  22. ox.security — A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads
  23. Hack Noon — Upwind First to Detect One of the Most Deceptive npm Compromises Yet Recorded
  24. phoenix.security — Mini Shai-Hulud keyv/cacheable npm Compromise (No CVE Assigned): Self-Propagating Worm Steals CI, Cloud, and Developer Credentials
  25. techjacksolutions.com — npm / Open Source Ecosystem (Shai-Hulud Supply Chain Worm) Vulnerability Rollup (2026-08-04)
  26. Microsoft Security Blog — ChainDrop supply chain compromise: Anatomy of a self-propagating worm
  27. Malware News — Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
  28. SOCFortress — The Shai-Hulud NPM Supply Chain Attack: Analysis and Indicators
  29. Malware News — Shai-Hulud Returns: When Software Trust Becomes the Attack Surface
  30. arcticwolf.com — Active Supply Chain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required
  31. unit42.paloaltonetworks.com — ChainDrop: Inside a Self-Propagating npm Worm
  32. techjacksolutions.com — npm Supply Chain Worm 'Shai-Hulud' Propagates Across 1,684 Package Versions via Credential Theft and SLSA Provenance Abuse
  33. xploitzone.com — ChainDrop NPM Worm SLSA Provenance Bypass Ethereum C2 400 Packages IDE Persistence
  34. Malware News — Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
  35. sec-tec.co.uk — The Register: ChainDrop worm crawls into npm supply chain, evades standard defenses
  36. Malware News — Shai-Hulud in the Wild: What Security and IR Teams Need to Know
  37. computerweekly.com — Amazon pins multiple open source compromises on North Korea
  38. bleepingcomputer.com — Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
  39. SecurityWeek — North Korean Hackers Target Open Source Developers in Supply Chain Attacks
  40. Unit42
  41. Arcticwolf
  42. Threatlocker
  43. Microsoft
  44. Osintsights
  45. Cybersecurity News — North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
  46. Sonatype
  47. Daily
  48. Threats
  49. Developer-tech
  50. Ground
  51. Cyberpress
  52. feeds.feedburner.com — North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
  53. Bellatorcyber
  54. Github
  55. Threats
  56. Darkreading
  57. Podcasts
  58. Mallory
  59. Github
  60. Breached
  61. Youtube
  62. Socket
  63. Reddit
  64. Medium
  65. Elastic
  66. Blog
  67. Medium
  68. Reddit
  69. Panther
  70. Stairwell
  71. Socdefenders
  72. Cybersecuritynews
  73. Kudelskisecurity
  74. Unit42
  75. Cyberpress
  76. News
  77. Fag-consult
  78. Ourservices
  79. Kahutek
  80. Isc2gauteng
  81. Agentbreach
  82. About
  83. Pentagondesign
  84. helpnetsecurity.com — AI agents tricked into recommending malicious GitHub repositories
  85. Corelight
  86. Flashpoint
  87. Kudelskisecurity
  88. Flare
  89. Trmlabs
  90. Margin
  91. Justice
  92. Home
  93. Unit42
  94. Revanthselvam
  95. Anthropic
  96. Daily
  97. Bleepingcomputer
  98. Techzine
  99. Trendmicro
  100. cybersecuritydive.com — As data breaches grow costlier, ungoverned AI creates new risks
  101. cyberscoop.com — A little-known npm package was North Korea’s warm-up act for the axios hack
  102. Aws
  103. Seceon
  104. Youtube
  105. Neworleanscitybusiness
  106. Medium
  107. Esecurityplanet
  108. Reddit
  109. Nextgov
  110. Safedep
  111. Thehackernews
  112. Interlynk
  113. Reddit
  114. Aiweekly
  115. Infosecurity-magazine
  116. Secarma
  117. Utopiats
  118. Meritalk
  119. news.ycombinator.com — Keyv and friends compromised in active Shai-Hulud supply chain attack
  120. bleepingcomputer.com — Massive ChainDrop npm supply-chain attack infects hundreds of packages
  121. Splunk
  122. Research
  123. Expel
  124. Strobes
  125. Securitylabs
  126. Wiz
  127. Trendmicro
  128. Securityboulevard
  129. Thenextweb
  130. Upwind
  131. Finanzwire
  132. Digital
  133. Openai
  134. Sygnia
  135. Xygeni
  136. Stepsecurity
  137. Elastic
  138. Infosecurity-magazine
  139. Secarma
  140. Beazley
  141. Socket
  142. Cycode
  143. Cloudsmith
  144. Veracode
  145. Zscaler
  146. Hivepro
  147. Ampcuscyber
  148. Sangfor
  149. Unit42
  150. Falconfeeds
  151. SecurityWeek — Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

LINK COPIED TO CLIPBOARD