North Korea-Linked PolinRider Campaign Hides JavaScript Loaders in Open Source Repositories
VPN Central [Unofficial]
July 4, 2026
Security researchers have uncovered a North Korea-linked supply chain campaign that plants hidden JavaScript loaders inside open source repositories and package releases used by developers. The campaign, tracked as PolinRider, has spread across npm, Packagist, Go modules, and a Chrome extension, according to a new Socket report. The activity has been linked to the broader […]
The post North Korea-Linked PolinRider Campaign Hides JavaScript Loaders in Open Source Repositories appeared first on VPN Central.
Discussion in the ATmosphere