PolinRider Caused Dozens of npm, Go, PHP Compromises

    Date: 08/03/2026

    Severity: High

    Summary

    Attackers compromised legitimate Joyfill packages and inserted malware that deploys a remote access trojan (RAT) on developer systems. Researchers linked the activity to the DPRK-associated PolinRider campaign based on indicators such as Tron, Aptos, and BNB Smart Chain transactions. Unlike previous PolinRider operations that relied on typosquatting and malicious repositories, this campaign involved the takeover of legitimate package accounts. For months, the group has targeted developers through fake job interviews, poisoned code repositories, malicious VS Code tasks, and deceptive software packages. The objective is to compromise developer machines and accounts, enabling the theft of credentials, repository cloning, and the insertion of backdoored code. By maintaining persistent access across numerous systems, the actors have effectively built a large network of compromised developer environments to support future operations.

    Indicators of Compromise (IOC) List

    Domains/URLs

    api.trongrid.io

    fullnode.mainnet.aptoslabs.com

    bsc-dataseed.binance.org

    bsc-rpc.publicnode.com

    IP Address 

    166.88.134.62

    23.27.13.43

    198.105.127.210

    23.27.202.27

    Hash  

    53abf37710d6f2e35694fbe7cfaf1108127cbc001ce3e6bf994d0486cae5a0e8

    13e9a3c41e038bf9d8fcb0831305819819e4f7f4452bc20a04b9bf2756ee22e8

    Filepaths

    /$/boot

    /$/{id}

    /verify-human/{channel}

    /snv 

    /u/e

    /u/f

    /d/python.zip

    /d/python.7z

    /d/7zr.exe

    XOR keys

    2[gWfGj;<:-93Z^C

    ThZG+0jfXE6VAGOJ

    TRON wallets

    TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP

    TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG

    TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v

    Aptos addresses

    0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e

    0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3

    0x533b2dbcaeff19cd1f799234a27b578d713d8fcaa341b7501e4526106483e0b1

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "fullnode.mainnet.aptoslabs.com" or url like "fullnode.mainnet.aptoslabs.com" or siteurl like "fullnode.mainnet.aptoslabs.com" or domainname like "api.trongrid.io" or url like "api.trongrid.io" or siteurl like "api.trongrid.io" or domainname like "bsc-dataseed.binance.org" or url like "bsc-dataseed.binance.org" or siteurl like "bsc-dataseed.binance.org" or domainname like "bsc-rpc.publicnode.com" or url like "bsc-rpc.publicnode.com" or siteurl like "bsc-rpc.publicnode.com"

    Detection Query 2 :

    dstipaddress IN ("23.27.202.27","166.88.134.62","23.27.13.43","198.105.127.210") or srcipaddress IN ("23.27.202.27","166.88.134.62","23.27.13.43","198.105.127.210")

    Detection Query 3 :

    sha256hash IN ("13e9a3c41e038bf9d8fcb0831305819819e4f7f4452bc20a04b9bf2756ee22e8","53abf37710d6f2e35694fbe7cfaf1108127cbc001ce3e6bf994d0486cae5a0e8")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "/$/boot" or objectname like "/$/{%}" or objectname like "/verify-human/{%}" or objectname like "/snv" or objectname like "/u/e" or objectname like "/u/f" or objectname like "/d/python.zip" or objectname like "/d/python.7z" or objectname like "/d/7zr.exe") 

    Detection Query 5 :

    technologygroup = "EDR" and (objectname like "/$/boot" or objectname like "/$/{%}" or objectname like "/verify-human/{%}" or objectname like "/snv" or objectname like "/u/e" or objectname like "/u/f" or objectname like "/d/python.zip" or objectname like "/d/python.7z" or objectname like "/d/7zr.exe") 

    Reference:    

    https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-gocompromises                              


    Tags

    MalwareThreat ActorRATNode Package Manager (NPM)DPRKCredential Harvesting

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags