- PolinRider is a DPRK-linked supply-chain campaign that takes over legitimate GitHub accounts and injects obfuscated JavaScript loaders into repositories.
- Initially confined to GitHub, the campaign expanded to multiple package ecosystems including Packagist, Go modules, npm, and PyPI without evolving its malware.
- Ecosystems like Go and Packagist are particularly vulnerable because they resolve packages directly from Git repos, making GitHub account takeovers equivalent to publishing access.
- The malware uses methods such as appending JavaScript to config files, fake .woff2 font files, .vscode/tasks.json triggers, and typosquatted npm dependencies.