News › security

North Korean Hackers Target Developers with Malicious Packages in PolinRider Campaign

By Zayden R., July 5, 2026

North Korean hackers have released 108 malicious packages and browser extensions targeting npm, Packagist, Go, and Chrome, continuing their PolinRider campaign. This poses a significant risk to developers using these platforms.

In a concerning development for the software development community, North Korean hackers have been identified as the source of 108 malicious packages and browser extensions. These packages, distributed across npm, Packagist, Go, and Google Chrome, are part of the ongoing PolinRider campaign. This activity highlights a persistent threat to developers and users relying on these platforms.

The attackers, linked to the Contagious Interview campaign, have been actively compromising maintainer accounts to publish these harmful packages. This method allows them to infiltrate widely-used software repositories and potentially reach a broad audience. The campaign is not showing signs of slowing down; experts warn that more malicious packages are likely to appear as the threat actors continue their efforts.

Technical details reveal that these packages are crafted to exploit vulnerabilities in the software supply chain, a tactic that has seen increased use in recent years. By gaining access to legitimate accounts, the attackers can introduce malicious code that might bypass traditional security measures. This is a stark reminder of the importance of maintaining robust security practices, especially within open-source communities.

For developers and sysadmins, this serves as a crucial alert to scrutinize dependencies and maintainers' credentials. Keeping software up-to-date and employing automated tools to detect suspicious activities can help mitigate such risks. The community must remain vigilant, as the implications of these attacks can be severe, potentially compromising systems and exposing sensitive data.

Sources

Practice this on a real machine

The Linux Camp teaches these topics as hands-on labs on real virtual machines, verified as you type.