North Korean Hackers Deploy 108 Malicious Packages in PolinRider Campaign

North Korean hackers linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple platforms as part of their ongoing PolinRider operation. These malicious artifacts are being actively distributed via compromised maintainer accounts on npm, Packagist, Go, and Chrome Web Store.

Why it matters

This active campaign highlights the growing risk of supply chain compromise through trusted software repositories.

SOC impact

SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.

Recommended actions

  1. Determine whether affected users, domains, or third-party providers intersect with your organization.
  2. Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
  3. Review MFA coverage and initiate credential resets where exposure is confirmed.

Executive Summary

North Korean hackers linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple platforms as part of their ongoing PolinRider operation. These malicious artifacts are being actively distributed via compromised maintainer accounts on npm, Packagist, Go, and Chrome Web Store. This active campaign highlights the growing risk of supply chain compromise through trusted software repositories.

SOC Impact

SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.

Credential and Exposure Checks

  • Determine whether affected users, domains, or third-party providers intersect with your organization.
  • Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
  • Review MFA coverage and initiate credential resets where exposure is confirmed.

Why It Matters

This active campaign highlights the growing risk of supply chain compromise through trusted software repositories.

Source