NPM Isn't Prepared For North Korean PolinRider Attack
2026-08-25 • Open Source Malware •
https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack
PolinRider operators compromised a legitimate developer's GitHub identity and repeatedly used it to distribute DPRK-attributed NullReceiver malware through `fetch-page-assets` and other npm packages. Although npm removed version 1.2.9, the underlying `.vscode/tasks.json` launcher persisted, and later releases added an obfuscated payload to `babel.config.cjs` that could execute during builds or tests. Coordinated force-pushes affected all seven active repositories owned by the developer, demonstrating account-wide control rather than a one-time package compromise. OpenSourceMalware argues that version-specific advisories and tarball takedowns cannot contain a campaign already confirmed across 4,367 repositories and 2,152 owners.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://github.com/DiogoAngelim… | 2026-08-25 | 2026-08-25 |
| URL | https://github.com/DiogoAngelim… | 2026-08-25 | 2026-08-25 |
| URL | https://github.com/DiogoAngelim… | 2026-08-25 | 2026-08-25 |
| URL | https://github.com/DiogoAngelim… | 2026-08-25 | 2026-08-25 |
| URL | https://github.com/DiogoAngelim… | 2026-08-25 | 2026-08-25 |
| URL | https://github.com/DiogoAngelim… | 2026-08-25 | 2026-08-25 |
| URL | https://github.com/DiogoAngelim | 2026-08-25 | 2026-08-25 |
| HASH | 0272b9f2b1a0dda93baebf3bae505e2… | 2026-08-25 | 2026-08-25 |
| HASH | 6df5b2c9c172d3b822494c3ef9083db… | 2026-08-25 | 2026-08-25 |
| HASH | 5e226620d2e360205cc8634e3c581a0… | 2026-08-25 | 2026-08-25 |
| HASH | 9fbb31129c04e8eb1a50519fc864c74… | 2026-08-25 | 2026-08-25 |
| HASH | f5c6be4753d6613c97f1b10c4d93a5d… | 2026-08-25 | 2026-08-25 |
| WALLET | 0xa322e5f3d311d3080e6f0121063e9… | 2026-08-02 | 2026-08-25 |