Post
CRITICAL ⚡ MUST-KNOW

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

· supply-chain · npm · malware

North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist, Go, and the Chrome Web Store, in an ongoing operation tracked as PolinRider. The campaign remains active, with new malicious packages continuing to appear as the actors compromise maintainer accounts to distribute them. The spread across multiple package ecosystems and an official browser extension store makes this a significant supply chain risk. Teams should audit recently added dependencies from unfamiliar or newly-active maintainers, particularly in npm and Go ecosystems.