<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd" -->

---
title: PolinRider: North Korea-Linked Supply Chain Campaign...
description: Socket&#x27;s Threat Research Team has uncovered PolinRider, a North Korea-linked supply chain campaign tied to the Contagious Interview / Famous Chollima cluster....
canonical: https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: PolinRider: North Korea-Linked Supply Chain Campaign Expands... | daily.dev
og:description: Socket&#x27;s Threat Research Team has uncovered PolinRider, a North Korea-linked supply chain campaign tied to the Contagious Interview / Famous Chollima cluster....
og:url: https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd
og:image: https://api.daily.dev/og/posts/xKZgY7UCD.png
og:image:alt: PolinRider: North Korea-Linked Supply Chain Campaign Expands...
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# PolinRider: North Korea-Linked Supply Chain Campaign Expands...

**[Socket](https://daily.dev/sources/socketdev)** · 8 min read · 0 upvotes · 0 comments

## Summary

Socket's Threat Research Team has uncovered PolinRider, a North Korea-linked supply chain campaign tied to the Contagious Interview / Famous Chollima cluster. The campaign has expanded beyond npm into Go modules, Packagist, and Chrome extensions, with 162 malicious release artifacts found across 108 packages. Threat actors compromise maintainer accounts, plant obfuscated JavaScript loaders hidden in fake .woff2 font files or config files, and trigger execution via VS Code task files. Git history is rewritten using force pushes and anti-dated commits to obscure malicious changes. Payloads use blockchain RPC infrastructure (TRON, Aptos, BNB Smart Chain) to retrieve and execute encrypted second-stage malware including DEV#POPPER and OmniStealer, enabling credential theft, C2 communication, and wallet exfiltration. Affected teams should treat environments as compromised, rotate all secrets from a clean machine, audit VS Code tasks, and review GitHub Activity logs rather than relying on visible commit history.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands>

## Similar posts on daily.dev

- [North Korea’s Contagious Interview Campaign Spreads Across 5...](https://daily.dev/posts/north-korea-s-contagious-interview-campaign-spreads-across-5--8ubvqs6zc) · Socket · 3 upvotes · 1 comments
- [North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets](https://daily.dev/posts/north-korea-linked-npm-packages-impersonate-rollup-polyfill-tools-to-steal-developer-secrets-mvjcouuhx) · The Next Web · 2 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#golang](https://daily.dev/tags/golang), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"PolinRider: North Korea-Linked Supply Chain Campaign Expands...","url":"https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd"},"datePublished":"2026-07-01T20:43:14.326Z","dateModified":"2026-07-01T20:59:13.217Z","description":"Socket's Threat Research Team has uncovered PolinRider, a North Korea-linked supply chain campaign tied to the Contagious Interview / Famous Chollima cluster....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ae12b00a9cd81a2290bf135124e5d41e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ae12b00a9cd81a2290bf135124e5d41e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Socket","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Socket","logo":"https://media.daily.dev/image/upload/s---oEn9czC--/f_auto/v1716187892/logos/socketdev","url":"https://daily.dev/sources/socketdev"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/polinrider-north-korea-linked-supply-chain-campaign-expands--xkzgy7ucd","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,golang,malware,npm","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Socket","item":"https://daily.dev/sources/socketdev"},{"@type":"ListItem","position":3,"name":"PolinRider: North Korea-Linked Supply Chain Campaign Expands..."}]}
```

