PolinRider Caused Dozens of npm and Go Compromises

2026-07-31 Open Source Malware

https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises

Thumbnail for PolinRider Caused Dozens of npm and Go Compromises

DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages through reused XOR keys, TRON wallets, blockchain dead drops, a fake font-file loader, and the `temp_auto_push.bat` propagation script. The payload chain delivered DEV#POPPER, InvisibleFerret, and OmniStealer for remote access, credential theft, wallet exfiltration, and keylogging. Investigators also found widespread backdating of malicious Go commits, while Go's permanent proxy cache continued serving affected modules after their GitHub repositories disappeared.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 13e9a3c41e038bf9d8fcb0831305819… 2026-07-31 2026-07-31
HASH 53abf37710d6f2e35694fbe7cfaf110… 2026-07-31 2026-07-31
URL http://23.27.13.43/$/boot 2026-07-28 2026-07-31
IPv4 23.27.13.43 2026-07-28 2026-07-31
IPv4 166.88.134.62 2026-07-28 2026-07-31
WALLET 0x533b2dbcaeff19cd1f799234a27b5… 2026-06-16 2026-07-31
WALLET TA48dct6rFW8BXsiLAtjFaVFoSuryMj… 2026-06-16 2026-07-31
WALLET 0x3f0e5781d0855fb460661ac632573… 2026-03-06 2026-07-31
WALLET 0xbe037400670fbf1c32364f7629759… 2026-03-06 2026-07-31
WALLET TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… 2026-03-06 2026-07-31
WALLET TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… 2026-03-06 2026-07-31
IPv4 198.105.127.210 2026-03-05 2026-07-31
IPv4 23.27.202.27 2025-10-20 2026-07-31

Related Actors

Related Reports

« Back