NPM Isn't Prepared For North Korean PolinRider Attack

2026-08-25 Open Source Malware

https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack

Thumbnail for NPM Isn't Prepared For North Korean PolinRider Attack

PolinRider operators compromised a legitimate developer's GitHub identity and repeatedly used it to distribute DPRK-attributed NullReceiver malware through `fetch-page-assets` and other npm packages. Although npm removed version 1.2.9, the underlying `.vscode/tasks.json` launcher persisted, and later releases added an obfuscated payload to `babel.config.cjs` that could execute during builds or tests. Coordinated force-pushes affected all seven active repositories owned by the developer, demonstrating account-wide control rather than a one-time package compromise. OpenSourceMalware argues that version-specific advisories and tarball takedowns cannot contain a campaign already confirmed across 4,367 repositories and 2,152 owners.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://github.com/DiogoAngelim… 2026-08-25 2026-08-25
URL https://github.com/DiogoAngelim… 2026-08-25 2026-08-25
URL https://github.com/DiogoAngelim… 2026-08-25 2026-08-25
URL https://github.com/DiogoAngelim… 2026-08-25 2026-08-25
URL https://github.com/DiogoAngelim… 2026-08-25 2026-08-25
URL https://github.com/DiogoAngelim… 2026-08-25 2026-08-25
URL https://github.com/DiogoAngelim 2026-08-25 2026-08-25
HASH 0272b9f2b1a0dda93baebf3bae505e2… 2026-08-25 2026-08-25
HASH 6df5b2c9c172d3b822494c3ef9083db… 2026-08-25 2026-08-25
HASH 5e226620d2e360205cc8634e3c581a0… 2026-08-25 2026-08-25
HASH 9fbb31129c04e8eb1a50519fc864c74… 2026-08-25 2026-08-25
HASH f5c6be4753d6613c97f1b10c4d93a5d… 2026-08-25 2026-08-25
WALLET 0xa322e5f3d311d3080e6f0121063e9… 2026-08-02 2026-08-25

Related Actors

Related Reports

« Back