INFO • SecOpsAI Intelligence

PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems

PolinRider expands across npm, Packagist, Go modules, and Chrome extensions, using hidden loaders to target developer environments.

Info By Socket Blog 1 min read Published: 2026-07-01 Updated: 2026-07-02
Security News Supply Chain Research npm composer go

Source Metadata

Why It Matters

  • Source type: Security News
  • Severity hint: info (Default source severity.)
  • Extracted signals: none detected deterministically

What SecOpsAI Can Detect

SecOpsAI can compare affected package names and versions against emergency advisories, lockfiles, package manifests, package registry changes, and supply-chain SOC findings.

Extracted Intelligence

CVEs

  • None found deterministically; reviewer should confirm source details.

Affected Packages Or Products

  • npm
  • Packagist

IOCs

  • None found deterministically; reviewer should add source-backed indicators if present.

Recommended Actions

  • Block affected package names or versions when source-backed version details are available.
  • Inspect lockfiles, manifests, and CI dependency caches for affected package references.
  • Rotate package-manager, CI, and registry credentials if compromise or token theft is reported.
  • Run SecOpsAI supply-chain advisory checks for extracted package names.
  • Review extracted package references: npm.

Operator Commands

secopsai triage summary
secopsai research preflight
secopsai supply-chain advisory list
secopsai blog news-review show news-80d28381a6d4f840-polinrider-north-korea-linked-supply-chain-campaign-expands-across-o

References

Comments

Comments are moderated before publication. Do not post secrets, tokens, customer data, or exploit payloads.