North Korean Hackers Launch PolinRider Supply-Chain Attack to Steal Cryptocurrency
PolinRider is a software supply-chain attack that the North Korean hacking group Contagious Interview, also known as Famous Chollima, has conducted since December 2025. The group uses fake recruitment campaigns and compromised accounts belonging to open-source maintainers to infiltrate development environments and steal corporate credentials, source code and cryptocurrency wallets. The threat can spread through package dependencies into corporate CI/CD systems.
On July 7, 2026, iThome cited a Socket investigation showing that PolinRider had infiltrated 108 packages across NPM, Packagist, Go modules and the Chrome Web Store, releasing 162 malicious versions. The campaign remained active. Separately that day, JFrog disclosed six malicious NPM packages masquerading as Rollup tools. No figures are currently available for the number of victims or the value of losses.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.