Date: 08/03/2026
Severity: High
Summary
Attackers compromised legitimate Joyfill packages and inserted malware that deploys a remote access trojan (RAT) on developer systems. Researchers linked the activity to the DPRK-associated PolinRider campaign based on indicators such as Tron, Aptos, and BNB Smart Chain transactions. Unlike previous PolinRider operations that relied on typosquatting and malicious repositories, this campaign involved the takeover of legitimate package accounts. For months, the group has targeted developers through fake job interviews, poisoned code repositories, malicious VS Code tasks, and deceptive software packages. The objective is to compromise developer machines and accounts, enabling the theft of credentials, repository cloning, and the insertion of backdoored code. By maintaining persistent access across numerous systems, the actors have effectively built a large network of compromised developer environments to support future operations.
Indicators of Compromise (IOC) List
Domains/URLs | api.trongrid.io fullnode.mainnet.aptoslabs.com bsc-dataseed.binance.org bsc-rpc.publicnode.com |
IP Address | 166.88.134.62 23.27.13.43 198.105.127.210 23.27.202.27 |
Hash | 53abf37710d6f2e35694fbe7cfaf1108127cbc001ce3e6bf994d0486cae5a0e8
13e9a3c41e038bf9d8fcb0831305819819e4f7f4452bc20a04b9bf2756ee22e8
|
Filepaths | /$/boot /$/{id} /verify-human/{channel} /snv /u/e /u/f /d/python.zip /d/python.7z /d/7zr.exe |
XOR keys | 2[gWfGj;<:-93Z^C ThZG+0jfXE6VAGOJ |
TRON wallets | TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v |
Aptos addresses | 0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e 0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3 0x533b2dbcaeff19cd1f799234a27b578d713d8fcaa341b7501e4526106483e0b1 |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "fullnode.mainnet.aptoslabs.com" or url like "fullnode.mainnet.aptoslabs.com" or siteurl like "fullnode.mainnet.aptoslabs.com" or domainname like "api.trongrid.io" or url like "api.trongrid.io" or siteurl like "api.trongrid.io" or domainname like "bsc-dataseed.binance.org" or url like "bsc-dataseed.binance.org" or siteurl like "bsc-dataseed.binance.org" or domainname like "bsc-rpc.publicnode.com" or url like "bsc-rpc.publicnode.com" or siteurl like "bsc-rpc.publicnode.com" |
Detection Query 2 : | dstipaddress IN ("23.27.202.27","166.88.134.62","23.27.13.43","198.105.127.210") or srcipaddress IN ("23.27.202.27","166.88.134.62","23.27.13.43","198.105.127.210") |
Detection Query 3 : | sha256hash IN ("13e9a3c41e038bf9d8fcb0831305819819e4f7f4452bc20a04b9bf2756ee22e8","53abf37710d6f2e35694fbe7cfaf1108127cbc001ce3e6bf994d0486cae5a0e8")
|
Detection Query 4 : | datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "/$/boot" or objectname like "/$/{%}" or objectname like "/verify-human/{%}" or objectname like "/snv" or objectname like "/u/e" or objectname like "/u/f" or objectname like "/d/python.zip" or objectname like "/d/python.7z" or objectname like "/d/7zr.exe") |
Detection Query 5 : | technologygroup = "EDR" and (objectname like "/$/boot" or objectname like "/$/{%}" or objectname like "/verify-human/{%}" or objectname like "/snv" or objectname like "/u/e" or objectname like "/u/f" or objectname like "/d/python.zip" or objectname like "/d/python.7z" or objectname like "/d/7zr.exe") |
Reference:
https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-gocompromises