Skip to content
North Korean hackers expand supply chain attack campaign across ecosystems

North Korean hackers expand supply chain attack campaign across ecosystems

Ground.News • July 3, 2026

Security researchers at JFrog have identified a set of malicious npm packages linked to North Korean threat actors that impersonate legitimate Rollup polyfill tooling to steal developer credentials and enable remote access to compromised machines. The packages, named “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core,” mimic the legitimate “rollup-plugin-polyfill-node” project down to its description, repository metadata, and pack…

North Korean-linked cybercriminals have expanded a long-running campaign targeting software supply chains across multiple open-source software ecosystems, exposing software developers and organizations that rely on open-source software packages to a broader range of attacks. In a report published Wednesday, U.S. security firm Socket said it identified 162 malicious release artifacts across 108 packages and browser […]

A new wave of supply chain attacks is spreading across the open source world, and this time the target is developers themselves. Security researchers have uncovered a campaign called PolinRider that hides malicious JavaScript loaders inside trusted code repositories, waiting for unsuspecting developers to run them. The campaign has been linked to North Korean threat actors tied to the broader Contagious Interview and Famous Chollima activity clu…

A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts across 108 unique packages and extensions in npm, Packagist, Go modules, and a Chrome extension, linking this activity to the broader North Korean Contagious Interview […] The post Hackers Compromise G…

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

APT Groups (1)

Attack Types (1)

Countries (1)

Tools (1)