North Korean hackers push 108 malicious packages and browser extensions.
North Korean threat actors linked to the “Contagious Interview” campaign have published 108 malicious packages and extensions across npm, Packagist, Go, and Chrome. The campaign, called PolinRider, targets developers and crypto-adjacent users through poisoned repositories, fake tooling, and malicious VS Code tasks. Researchers say the attackers hide JavaScript loaders through whitespace padding, fake font files, and repository history manipulation. The payload chain can fetch second-stage malware including DEV#POPPER RAT and OmniStealer through blockchain infrastructure. The main defensive advice is to treat affected developer machines as compromised, rotate secrets from a clean system, rebuild from trusted lockfiles, and audit .vscode/tasks.json plus suspicious config-file changes.