Socket's Threat Research Team has uncovered PolinRider, a North Korea-linked supply chain campaign tied to the Contagious Interview / Famous Chollima cluster. The campaign has expanded beyond npm into Go modules, Packagist, and Chrome extensions, with 162 malicious release artifacts found across 108 packages. Threat actors compromise maintainer accounts, plant obfuscated JavaScript loaders hidden in fake .woff2 font files or config files, and trigger execution via VS Code task files. Git history is rewritten using force pushes and anti-dated commits to obscure malicious changes. Payloads use blockchain RPC infrastructure (TRON, Aptos, BNB Smart Chain) to retrieve and execute encrypted second-stage malware including DEV#POPPER and OmniStealer, enabling credential theft, C2 communication, and wallet exfiltration. Affected teams should treat environments as compromised, rotate all secrets from a clean machine, audit VS Code tasks, and review GitHub Activity logs rather than relying on visible commit history.