← Back to Daily Briefing

North Korean state-sponsored actors, associated with the PolinRider operation and Contagious Interview campaign, are executing a multi-vector supply chain offensive targeting the developer ecosystem. By compromising GitHub maintainer accounts and utilizing package impersonation, the actors injected malicious code into npm, Packagist, and Go ecosystems. The campaign specifically targets modern toolchains, including Claude Code and GitHub CLI, to deploy Windows Remote Access Trojans (RATs), Linux native C rootkits, and credential stealers aimed at SSH keys and developer tokens. With over 108 unique malicious packages and extensions identified, the operation seeks persistent high-level access to DevOps environments and AI-assisted coding workflows.

  • Incident Overview: Operation PolinRider

    • Attributed to North Korean state-sponsored threat actors linked to the "Contagious Interview" campaign.
    • Identified 108 unique malicious packages and browser extensions distributed across multiple registries.
    • Operation remains active, with threat actors continuously hijacking maintainer accounts to release infected versions.
  • Attack Vectors & Delivery Mechanics

    • Account Hijacking: Compromising legitimate GitHub maintainer accounts to publish malicious updates to trusted packages.
    • Ecosystem Poisoning: Utilizing impersonation and typosquatting across npm, Packagist, and Go package managers.
    • Browser-Based Vectors: Deployment of malicious Google Chrome extensions to facilitate initial access and data theft.
  • Technical Payload Analysis

    • Windows RAT: High-level Remote Access Trojans used for command execution and system control.
    • Linux C Rootkit: Deployment of native C-based rootkits to ensure stealthy, low-level persistence on developer machines.
    • Credential Exfiltration: Specialized stealers designed to target SSH keys and developer-specific authentication tokens.
  • Targeted Toolchains & Impact

    • AI-Assisted Coding: Specifically targeting Claude Code to intercept sensitive prompts, API keys, or source code.
    • CLI Tooling: Targeting GitHub CLI to gain unauthorized access to private repositories and CI/CD pipelines.
    • Demographic Focus: High-value targets include software developers, DevOps engineers, and AI practitioners.
  • Defensive Actions & Mitigation

    • Implement strict dependency pinning and utilize lockfiles (e.g., package-lock.json) to prevent automatic updates to compromised versions.
    • Mandate hardware-based MFA for all maintainer accounts and developer identities.
    • Conduct audits of installed browser extensions and monitor for anomalous outbound traffic to unknown C2 infrastructure.

Related posts

  1. techjacksolutions.com — Concurrent npm Supply Chain Campaigns Deliver Windows RAT, Linux Rootkit, and Developer Credential Stealers, One Cluster Linked to North Korean PolinRider Operation
  2. feeds.feedburner.com — North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
  3. Medium LLM Security Tag — Prompt Injection Is No Longer Just a Chatbot Problem
  4. threat-modeling.com — North Korean PolinRider Campaign: 108 Malicious Packages Across npm, Packagist, Go, and Chrome — Active Supply Chain Attack
  5. techjacksolutions.com — AI Coding Roundup, July 4, 2026: Claude Code Goes Manual-First on Permissions, GitHub Copilot Ships Enterprise Governance Tools.
  6. gbhackers.com — Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
  7. News4Hackers — Critical GitHub Vulnerability Allows Prompt Injection in Agentic Workflows
  8. The Register - Security — Bug in top AI coding agents shows that Unix-era security headaches never really die
  9. threat-modeling.com — GhostApproval: Symlink Vulnerability in 6 AI Coding Assistants Allows Malicious Repos to Write to Arbitrary Files
  10. gbhackers.com — Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
  11. Google Cloud Security Community — Beyond Chat: Building an Autonomous SOC Analyst with Claude and the Google MCP
  12. feeds.feedburner.com — Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
  13. malware-log.hatenablog.com — North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections
  14. gbhackers.com — North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
  15. xploitzone.com — DPRK Fake IT Workers Exposed Stealer Logs Reveal North Korea Network Infrastructure
  16. cybersecurity.pk — FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
  17. gbhackers.com — AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
  18. cyberscoop.com — North Korea’s IT worker scheme funds Russia’s war effort
  19. SC Media — North Korea's IT worker scheme funds Russia's war effort, report finds
  20. threatlabsnews.xcitium.com — FakeGit Exposed: How 7,600 GitHub Repos Are Spreading SmartLoader Malware
  21. arXiv (Computer Science - Cryptography and Security) — ChainWatch: A Kill Chain-Aligned Sequential Detection Framework for Multi-Step Attacks in MCP-Based AI Agent Systems
  22. Malware News — Amazon uncovers broad North Korean hacking campaign against open-source software
  23. serisec.com — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
  24. The Record by Recorded Future — North Korean hackers behind major open-source supply chain attacks, Amazon says
  25. falconinternet.net — One Phished Maintainer, Four Poisoned Packages: Amazon Names North Korea in npm Supply Chain Campaign
  26. DEV Community — Stop Leaking Secrets into your LLM Context Windows
  27. eSecurity Planet — Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
  28. ox.security — A Massive Shai-Hulud Campaign Hits npm: +440 Packages Compromised, Over 2B Monthly Downloads
  29. Hack Noon — Upwind First to Detect One of the Most Deceptive npm Compromises Yet Recorded
  30. phoenix.security — Mini Shai-Hulud keyv/cacheable npm Compromise (No CVE Assigned): Self-Propagating Worm Steals CI, Cloud, and Developer Credentials
  31. techjacksolutions.com — npm / Open Source Ecosystem (Shai-Hulud Supply Chain Worm) Vulnerability Rollup (2026-08-04)
  32. Microsoft Security Blog — ChainDrop supply chain compromise: Anatomy of a self-propagating worm
  33. Malware News — Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
  34. SOCFortress — The Shai-Hulud NPM Supply Chain Attack: Analysis and Indicators
  35. Malware News — Shai-Hulud Returns: When Software Trust Becomes the Attack Surface
  36. arcticwolf.com — Active Supply Chain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required
  37. unit42.paloaltonetworks.com — ChainDrop: Inside a Self-Propagating npm Worm
  38. techjacksolutions.com — npm Supply Chain Worm 'Shai-Hulud' Propagates Across 1,684 Package Versions via Credential Theft and SLSA Provenance Abuse
  39. xploitzone.com — ChainDrop NPM Worm SLSA Provenance Bypass Ethereum C2 400 Packages IDE Persistence
  40. Malware News — Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
  41. sec-tec.co.uk — The Register: ChainDrop worm crawls into npm supply chain, evades standard defenses
  42. Malware News — Shai-Hulud in the Wild: What Security and IR Teams Need to Know
  43. computerweekly.com — Amazon pins multiple open source compromises on North Korea
  44. bleepingcomputer.com — Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
  45. arXiv (Computer Science - Cryptography and Security) — DualView: Preventing Indirect Prompt Injection in Personal AI Agents
  46. techjacksolutions.com — WriteOut: Writer Enterprise AI Platform Flaw Enabled Cross-Tenant Session Hijacking via Agent Preview Links
  47. techjacksolutions.com — GitLost: Unauthenticated Cross-Repository Data Exfiltration via GitHub Agentic Workflow Abuse
  48. threat-modeling.com — Friendly Fire and HalluSquatting: New Attacks Trick AI Coding Agents Into Running Attacker Code and Installing Malware
  49. News4Hackers — AI Hallucinations Exploited for Botnet Delivery: New Cybersecurity Threat
  50. penligent.ai
  51. penligent.ai — Claude Code Backdoor, Hidden Tracker, What the Prompt Steganography Actually Did
  52. SecurityWeek — North Korean Hackers Target Open Source Developers in Supply Chain Attacks
  53. SecurityWeek — ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
  54. Unit42
  55. Arcticwolf
  56. Threatlocker
  57. Microsoft
  58. Osintsights
  59. Cybersecurity News — North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
  60. Sonatype
  61. Daily
  62. Threats
  63. Developer-tech
  64. Ground
  65. Cyberpress
  66. feeds.feedburner.com — North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
  67. Bellatorcyber
  68. Github
  69. Threats
  70. Darkreading
  71. Podcasts
  72. Mallory
  73. Github
  74. Breached
  75. Youtube
  76. Socket
  77. Reddit
  78. Medium
  79. Medium
  80. Bighatgroup
  81. Oday-bakkour
  82. Code
  83. Learn
  84. Github
  85. Morphllm
  86. Github
  87. feeds.feedburner.com — GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
  88. Sqmagazine
  89. Infosecurity-magazine
  90. Devops
  91. Secarma
  92. Github
  93. Ienvi
  94. Medium
  95. Innovatecybersecurity
  96. Elastic
  97. Blog
  98. Medium
  99. Reddit
  100. Panther
  101. Stairwell
  102. Socdefenders
  103. Cybersecuritynews
  104. Kudelskisecurity
  105. Unit42
  106. Cyberpress
  107. News
  108. Fag-consult
  109. Ourservices
  110. Kahutek
  111. Isc2gauteng
  112. Agentbreach
  113. About
  114. Pentagondesign
  115. helpnetsecurity.com — AI agents tricked into recommending malicious GitHub repositories
  116. Corelight
  117. Flashpoint
  118. Kudelskisecurity
  119. Flare
  120. Trmlabs
  121. Margin
  122. Justice
  123. Home
  124. Unit42
  125. Revanthselvam
  126. Anthropic
  127. Daily
  128. Bleepingcomputer
  129. Techzine
  130. Trendmicro
  131. cybersecuritydive.com — As data breaches grow costlier, ungoverned AI creates new risks
  132. cyberscoop.com — A little-known npm package was North Korea’s warm-up act for the axios hack
  133. Aws
  134. Seceon
  135. Youtube
  136. Neworleanscitybusiness
  137. Medium
  138. Esecurityplanet
  139. Reddit
  140. Nextgov
  141. Safedep
  142. Thehackernews
  143. Interlynk
  144. Reddit
  145. Aiweekly
  146. Infosecurity-magazine
  147. Secarma
  148. Utopiats
  149. Meritalk
  150. news.ycombinator.com — Keyv and friends compromised in active Shai-Hulud supply chain attack
  151. bleepingcomputer.com — Massive ChainDrop npm supply-chain attack infects hundreds of packages
  152. Splunk
  153. Research
  154. Expel
  155. Strobes
  156. Securitylabs
  157. Wiz
  158. Trendmicro
  159. Securityboulevard
  160. Thenextweb
  161. Upwind
  162. Finanzwire
  163. Digital
  164. Openai
  165. Sygnia
  166. Xygeni
  167. Stepsecurity
  168. Elastic
  169. Infosecurity-magazine
  170. Secarma
  171. Beazley
  172. Socket
  173. Cycode
  174. Cloudsmith
  175. Veracode
  176. Zscaler
  177. Hivepro
  178. Ampcuscyber
  179. Sangfor
  180. Unit42
  181. Falconfeeds
  182. SecurityWeek — AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
  183. SecurityWeek — Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
  184. Dark Reading — AI Coding: Do Security Risks Outweigh Productivity Gains?

LINK COPIED TO CLIPBOARD