Threats · 70 days ago
The break is not just poisoned packages. The attackers are taking over maintainer accounts and rewriting repository history, so cleanup can miss malicious changes that now look like part of the project’s own past. That shifts the target from the package itself to the trust chain around it, including the developer machine that built or installed it.
Socket says PolinRider has now reached 162 malicious release artifacts across 108 unique packages, spanning npm, Packagist, Go modules, and a Chrome extension. The campaign uses compromised GitHub repositories, with some loaders hidden in configuration files and missed during cleanup. Packagist was added in the latest wave, including packages in the sevenspan namespace.
If your teams install from public registries, the risk is broader than a bad version number. A compromised maintainer account can expose registry, source-code, cloud, and CI/CD credentials, and those secrets can outlive the package cleanup itself.
3 sources covering this story
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers.
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The campaign spans npm, Packagist, Go, and Chrome, using obfuscated JavaScript loaders and VS Code tasks to deliver malware.
PolinRider: North Korea-Linked Supply Chain Campaign Expands...
PolinRider expands across npm, Packagist, Go modules, and Chrome extensions, using hidden loaders to target developer environments.
Part of the PlainSec briefing for 2026-07-06