North Korean state-sponsored actors, associated with the PolinRider operation and Contagious Interview campaign, are executing a multi-vector supply chain offensive targeting the developer ecosystem. By compromising GitHub maintainer accounts and utilizing package impersonation, the actors injected malicious code into npm, Packagist, and Go ecosystems. The campaign specifically targets modern toolchains, including Claude Code and GitHub CLI, to deploy Windows Remote Access Trojans (RATs), Linux native C rootkits, and credential stealers aimed at SSH keys and developer tokens. With over 108 unique malicious packages and extensions identified, the operation seeks persistent high-level access to DevOps environments and AI-assisted coding workflows.
-
Incident Overview: Operation PolinRider
- Attributed to North Korean state-sponsored threat actors linked to the "Contagious Interview" campaign.
- Identified 108 unique malicious packages and browser extensions distributed across multiple registries.
- Operation remains active, with threat actors continuously hijacking maintainer accounts to release infected versions.
-
Attack Vectors & Delivery Mechanics
- Account Hijacking: Compromising legitimate GitHub maintainer accounts to publish malicious updates to trusted packages.
- Ecosystem Poisoning: Utilizing impersonation and typosquatting across npm, Packagist, and Go package managers.
- Browser-Based Vectors: Deployment of malicious Google Chrome extensions to facilitate initial access and data theft.
-
Technical Payload Analysis
- Windows RAT: High-level Remote Access Trojans used for command execution and system control.
- Linux C Rootkit: Deployment of native C-based rootkits to ensure stealthy, low-level persistence on developer machines.
- Credential Exfiltration: Specialized stealers designed to target SSH keys and developer-specific authentication tokens.
-
Targeted Toolchains & Impact
- AI-Assisted Coding: Specifically targeting Claude Code to intercept sensitive prompts, API keys, or source code.
- CLI Tooling: Targeting GitHub CLI to gain unauthorized access to private repositories and CI/CD pipelines.
- Demographic Focus: High-value targets include software developers, DevOps engineers, and AI practitioners.
-
Defensive Actions & Mitigation
- Implement strict dependency pinning and utilize lockfiles (e.g.,
package-lock.json) to prevent automatic updates to compromised versions. - Mandate hardware-based MFA for all maintainer accounts and developer identities.
- Conduct audits of installed browser extensions and monitor for anomalous outbound traffic to unknown C2 infrastructure.
- Implement strict dependency pinning and utilize lockfiles (e.g.,
Related posts
- techjacksolutions.com — Concurrent npm Supply Chain Campaigns Deliver Windows RAT, Linux Rootkit, and Developer Credential Stealers, One Cluster Linked to North Korean PolinRider Operation
- feeds.feedburner.com — North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
- Medium LLM Security Tag — Prompt Injection Is No Longer Just a Chatbot Problem
- threat-modeling.com — North Korean PolinRider Campaign: 108 Malicious Packages Across npm, Packagist, Go, and Chrome — Active Supply Chain Attack
- techjacksolutions.com — AI Coding Roundup, July 4, 2026: Claude Code Goes Manual-First on Permissions, GitHub Copilot Ships Enterprise Governance Tools.
- gbhackers.com — Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
- News4Hackers — Critical GitHub Vulnerability Allows Prompt Injection in Agentic Workflows
- The Register - Security — Bug in top AI coding agents shows that Unix-era security headaches never really die
- threat-modeling.com — GhostApproval: Symlink Vulnerability in 6 AI Coding Assistants Allows Malicious Repos to Write to Arbitrary Files
- gbhackers.com — Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
- Google Cloud Security Community — Beyond Chat: Building an Autonomous SOC Analyst with Claude and the Google MCP
- feeds.feedburner.com — Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
- malware-log.hatenablog.com — North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections
- gbhackers.com — North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
- xploitzone.com — DPRK Fake IT Workers Exposed Stealer Logs Reveal North Korea Network Infrastructure
- cybersecurity.pk — FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- gbhackers.com — AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
- cyberscoop.com — North Korea’s IT worker scheme funds Russia’s war effort
- SC Media — North Korea's IT worker scheme funds Russia's war effort, report finds
- threatlabsnews.xcitium.com — FakeGit Exposed: How 7,600 GitHub Repos Are Spreading SmartLoader Malware
- arXiv (Computer Science - Cryptography and Security) — ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems
- Malware News — Amazon uncovers broad North Korean hacking campaign against open-source software
- serisec.com — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
- The Record by Recorded Future — North Korean hackers behind major open-source supply chain attacks, Amazon says
- falconinternet.net — One Phished Maintainer, Four Poisoned Packages: Amazon Names North Korea in npm Supply Chain Campaign
- DEV Community — Stop Leaking Secrets into your LLM Context Windows
- eSecurity Planet — Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
- ox.security — A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads
- Hack Noon — Upwind First to Detect One of the Most Deceptive npm Compromises Yet Recorded
- phoenix.security — Mini Shai-Hulud keyv/cacheable npm Compromise (No CVE Assigned): Self-Propagating Worm Steals CI, Cloud, and Developer Credentials
- techjacksolutions.com — npm / Open Source Ecosystem (Shai-Hulud Supply Chain Worm) Vulnerability Rollup (2026-08-04)
- Microsoft Security Blog — ChainDrop supply chain compromise: Anatomy of a self-propagating worm
- Malware News — Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
- SOCFortress — The Shai-Hulud NPM Supply Chain Attack: Analysis and Indicators
- Malware News — Shai-Hulud Returns: When Software Trust Becomes the Attack Surface
- arcticwolf.com — Active Supply Chain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required
- unit42.paloaltonetworks.com — ChainDrop: Inside a Self-Propagating npm Worm
- techjacksolutions.com — npm Supply Chain Worm 'Shai-Hulud' Propagates Across 1,684 Package Versions via Credential Theft and SLSA Provenance Abuse
- xploitzone.com — ChainDrop NPM Worm SLSA Provenance Bypass Ethereum C2 400 Packages IDE Persistence
- Malware News — Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
- sec-tec.co.uk — The Register: ChainDrop worm crawls into npm supply chain, evades standard defenses
- Malware News — Shai-Hulud in the Wild: What Security and IR Teams Need to Know
- computerweekly.com — Amazon pins multiple open source compromises on North Korea
- bleepingcomputer.com — Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
- arXiv (Computer Science - Cryptography and Security) — DualView: Preventing Indirect Prompt Injection in Personal AI Agents
- techjacksolutions.com — WriteOut: Writer Enterprise AI Platform Flaw Enabled Cross-Tenant Session Hijacking via Agent Preview Links
- techjacksolutions.com — GitLost: Unauthenticated Cross-Repository Data Exfiltration via GitHub Agentic Workflow Abuse
- threat-modeling.com — Friendly Fire and HalluSquatting: New Attacks Trick AI Coding Agents Into Running Attacker Code and Installing Malware
- News4Hackers — AI Hallucinations Exploited for Botnet Delivery: New Cybersecurity Threat
- penligent.ai
- penligent.ai — Claude Code Backdoor, Hidden Tracker, What the Prompt Steganography Actually Did
- SecurityWeek — North Korean Hackers Target Open Source Developers in Supply Chain Attacks
- SecurityWeek — ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
- Unit42
- Arcticwolf
- Threatlocker
- Microsoft
- Osintsights
- Cybersecurity News — North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
- Sonatype
- Daily
- Threats
- Developer-tech
- Ground
- Cyberpress
- feeds.feedburner.com — North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
- Bellatorcyber
- Github
- Threats
- Darkreading
- Podcasts
- Mallory
- Github
- Breached
- Youtube
- Socket
- Medium
- Medium
- Bighatgroup
- Oday-bakkour
- Code
- Learn
- Github
- Morphllm
- Github
- feeds.feedburner.com — GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
- Sqmagazine
- Infosecurity-magazine
- Devops
- Secarma
- Github
- Ienvi
- Medium
- Innovatecybersecurity
- Elastic
- Blog
- Medium
- Panther
- Stairwell
- Socdefenders
- Cybersecuritynews
- Kudelskisecurity
- Unit42
- Cyberpress
- News
- Fag-consult
- Ourservices
- Kahutek
- Isc2gauteng
- Agentbreach
- About
- Pentagondesign
- helpnetsecurity.com — AI agents tricked into recommending malicious GitHub repositories
- Corelight
- Flashpoint
- Kudelskisecurity
- Flare
- Trmlabs
- Margin
- Justice
- Home
- Unit42
- Revanthselvam
- Anthropic
- Daily
- Bleepingcomputer
- Techzine
- Trendmicro
- cybersecuritydive.com — As data breaches grow costlier, ungoverned AI creates new risks
- cyberscoop.com — A little-known npm package was North Korea’s warm-up act for the axios hack
- Aws
- Seceon
- Youtube
- Neworleanscitybusiness
- Medium
- Esecurityplanet
- Nextgov
- Safedep
- Thehackernews
- Interlynk
- Aiweekly
- Infosecurity-magazine
- Secarma
- Utopiats
- Meritalk
- news.ycombinator.com — Keyv and friends compromised in active Shai-Hulud supply chain attack
- bleepingcomputer.com — Massive ChainDrop npm supply-chain attack infects hundreds of packages
- Splunk
- Research
- Expel
- Strobes
- Securitylabs
- Wiz
- Trendmicro
- Securityboulevard
- Thenextweb
- Upwind
- Finanzwire
- Digital
- Openai
- Sygnia
- Xygeni
- Stepsecurity
- Elastic
- Infosecurity-magazine
- Secarma
- Beazley
- Socket
- Cycode
- Cloudsmith
- Veracode
- Zscaler
- Hivepro
- Ampcuscyber
- Sangfor
- Unit42
- Falconfeeds
- SecurityWeek — AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
- SecurityWeek — Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
- Dark Reading — AI Coding: Do Security Risks Outweigh Productivity Gains?