North Korean hackers expand supply chain attack campaign across ecosystems
8 Articles
8 Articles
North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets
Security researchers at JFrog have identified a set of malicious npm packages linked to North Korean threat actors that impersonate legitimate Rollup polyfill tooling to steal developer credentials and enable remote access to compromised machines. The packages, named “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core,” mimic the legitimate “rollup-plugin-polyfill-node” project down to its description, repository metadata, and pack…
North Korean hackers expand supply chain attack campaign across ecosystems
North Korean-linked cybercriminals have expanded a long-running campaign targeting software supply chains across multiple open-source software ecosystems, exposing software developers and organizations that rely on open-source software packages to a broader range of attacks. In a report published Wednesday, U.S. security firm Socket said it identified 162 malicious release artifacts across 108 packages and browser […]
The North Korean group Contagious Interview has released 108 packages and extensions trapped on npm, Packagist, Go and Chrome as part of the PolinRider campaign. Socket researchers have identified 162 malicious versions, disseminated via compromised maintainer accounts to infect developers' posts and steal their identifiers.
North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories
A new wave of supply chain attacks is spreading across the open source world, and this time the target is developers themselves. Security researchers have uncovered a campaign called PolinRider that hides malicious JavaScript loaders inside trusted code repositories, waiting for unsuspecting developers to run them. The campaign has been linked to North Korean threat actors tied to the broader Contagious Interview and Famous Chollima activity clu…
Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm, Packagist, Go modules, and a Chrome extension, linking this activity to the broader North Korean Contagious Interview […] The post Hackers Compromise G…
Coverage Details
Bias Distribution
- 50% of the sources lean Left, 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










