Briefing financecommunications
PolinRider: North Korea Floods npm, Go and Chrome With 108 Malicious Packages
A North Korean supply chain campaign tracked as PolinRider has distributed 162 malicious release artifacts across 108 packages in npm, Packagist, Go modules, and Chrome extensions, using VS Code auto-run tasks and blockchain-based command-and-control to deliver credential-stealing malware.