Mark RadarMARK RADAR
About
EN
Sign in

North Korean Hackers Launch PolinRider Supply-Chain Attack to Steal Cryptocurrency

3 reports · First detected 2026-07-07 · Last active 2026-07-07

PolinRider is a software supply-chain attack that the North Korean hacking group Contagious Interview, also known as Famous Chollima, has conducted since December 2025. The group uses fake recruitment campaigns and compromised accounts belonging to open-source maintainers to infiltrate development environments and steal corporate credentials, source code and cryptocurrency wallets. The threat can spread through package dependencies into corporate CI/CD systems.

On July 7, 2026, iThome cited a Socket investigation showing that PolinRider had infiltrated 108 packages across NPM, Packagist, Go modules and the Chrome Web Store, releasing 162 malicious versions. The campaign remained active. Separately that day, JFrog disclosed six malicious NPM packages masquerading as Rollup tools. No figures are currently available for the number of victims or the value of losses.

All Coverage

3 original reports

The Backstory

The history behind this event
North Korean Hackers Hide Crypto-Stealing Malware in SVG Files2026-07-30 · 1 reports · similarity 0.80

Contagious Interview is a long-running social-engineering campaign attributed to North Korean-linked hackers. Operatives pose as recruiters and use coding tests or job interviews to persuade software developers to download compromised projects. The targeting is significant because developers often hold source-code access, cloud credentials, browser sessions and cryptocurrency wallets, giving attackers both immediately valuable data and a potential route into corporate systems.

Elastic Security Labs disclosed the latest technique on July 29, 2026, saying attackers divided malicious code across multiple SVG image files to make repositories appear harmless. When a developer runs the project, the concealed components are reconstructed and loaded. The malware steals cryptocurrency-wallet data, browser credentials and cloud configurations before installing a remote-access backdoor. Elastic did not disclose the number of victims or any associated financial losses.

North Korea-Linked Hackers Hijack NPM Packages to Target Crypto2026-07-30 · 1 reports · similarity 0.89

NPM sits at the center of the JavaScript software ecosystem, where applications often inherit packages such as debug, chalk and axios through layers of dependencies. A compromised maintainer account can therefore distribute malicious code far beyond a single project. In this campaign, the injected browser payload monitored cryptocurrency activity and attempted to replace payment addresses with wallets controlled by the attackers, turning trust in open-source updates into a potentially broad theft channel.

Security researchers at Amazon Web Services and Google have linked the activity to North Korea-associated hackers, saying the group first tested its approach through the obscure typo-crypto package. On Sept. 8, 2025, attackers poisoned 18 packages including debug and chalk, which together recorded an estimated 2 billion weekly downloads. On March 31, 2026, two malicious axios releases remained available for about three hours; the affected release lines typically drew more than 100 million and 83 million downloads a week, respectively.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)