North Korean hackers are targeting open-source developers through PolinRider.

06.07.2026

North Korean hackers are targeting open-source developers through PolinRider. SecurityWeek reported that North Korean-linked hackers are targeting open-source developers with a campaign called PolinRider. According to Socket’s findings cited in the report, the campaign has…

Източник: www.securityweek.com

North Korean hackers are targeting open-source developers through PolinRider.

SecurityWeek reported that North Korean-linked hackers are targeting open-source developers with a campaign called PolinRider. According to Socket’s findings cited in the report, the campaign has compromised more than 100 legitimate open-source packages and repositories to deliver DEV#POPPER RAT and OmniStealer. The campaign spans npm, Packagist, Go modules, and Chrome extensions, and uses compromised maintainer accounts plus Git history rewriting to hide malicious changes. Socket identified 162 malicious release artifacts across 108 unique packages, and warned that affected developer environments may expose package-registry, source-code, cloud, and CI/CD credentials