threat-intel
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
High
Summary
North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This campaign leverages compromised developer accounts and GitHub repositories to deliver malware, including the DEV#POPPER RAT and OmniStealer, targeting cryptocurrency sectors and utilizing tactics like Git history rewriting and fake font files. The activity has already impacted over 1,951 GitHub repositories.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
