Dettaglio notizia

Data 05/07/2026
Titolo PolinRider Supply Chain Campaign Hijacks Developer Packages and Uses Blockchain Dead Drops
Contesto Researchers reported a broad software supply chain campaign targeting developers and cryptocurrency users through hijacked packages, browser extensions, and compromised maintainer accounts across ecosystems including npm, Go, Chrome, and Packagist. Socket linked the activity to North Korean actors associated with the Contagious Interview operation and identified 108 malicious packages and extensions spanning 162 release artifacts, while JFrog separately analyzed hijacked npm packages html-to-gutenberg 4.2.11 and fetch-page-assets 1.2.9 that were uploaded with malicious code. The activity appears to rely on account hijacking rather than compromise of GitHub itself, and some attacker infrastructure reportedly remains active even after certain packages were removed.

The malware chain used unusual delivery and evasion techniques aimed at developer workstations, including a VS Code folder-open task instead of standard npm lifecycle scripts, JavaScript hidden in a fake font file, and encrypted payload retrieval from blockchain transaction data on TRON, Aptos, and BNB Smart Chain. Researchers said the campaign deployed components including BeaverTail, DEV#POPPER RAT, OmniStealer, a socket.io backdoor, and a Python infostealer to steal browser credentials, password-manager contents, cryptocurrency wallet data, developer secrets, and operating system credential-store material across Windows, macOS, and Linux. Security firms warned that affected developer systems and credentials should be treated as fully compromised.
Fonte https://mallory.ai/stories/019f30fa-51d2-72b1-8e27-0f0d5481f4e6
Discussione? Parliamone sul Forum