North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign 34%

By Ravie Lakshmanan12%

7/4/2026, 11:17:00 AM

BS Summary: This article contains 24 faulty reasoning types, including Negativity Bias, Recency Bias, and Representativeness Heuristic, with Appeal to Authority as the most egregious example at 36.4% saturation with 263 hits. Analysis detected 2,086 faulty-reasoning hits from 722 analyzed words, generating a BS Score of 41.8% and a BS Rank of 34% (14,614 of 21,887 articles). This article is better (less manipulative) than 66.80% of the article peer group.

The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. 
"The campaign remains active, and new malicious packages are likely to continue appearing as threat actors compromise maintainer accounts, modify legitimate repositories, and publish infected package versions where they retain or obtain registry access," Socket security researcher Karlo Zanki said in an analysis published this week. 
The 162 malicious release artifacts span multiple release versions corresponding to 108 unique packages and extensions, including 19 npm libraries, 10 Composer packages, 61 Go modules, and one Google Chrome extension. 
Contagious Interview is the moniker assigned to a North Korea-aligned campaign that weaponizes job recruitment to target software developers and individuals working in the cryptocurrency sectors, using persuasive job interviews and assessments to trick them into executing malicious code. 
The activity is known to be active since at least 2023. 
Attackers masquerade as recruiters or collaborators on platforms like LinkedIn, GitHub, or freelance websites, often setting up elaborate front companies and AI-generated employee profiles to build trust and ultimately deliver malware. 
PolinRider was first flagged by the OpenSourceMalware team in March 2026, describing it as involving the threat actors implanting malicious obfuscated JavaScript payloads in hundreds of public GitHub repositories belonging to several unique owners to deliver a new variant of BeaverTail, a known JavaScript malware associated with Contagious Interview. 
As of April 11, 2026, the activity has compromised 1,951 public GitHub repositories associated with 1,047 unique owners, while also merging with another cluster called TaskJacker that drops malicious VS Code task files into GitHub users' existing repositories. 
The VS Code tasks include the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor. 
"The threat actor is not using stolen GitHub credentials," OpenSourceMalware said. 
"Instead, the victims have been compromised via a malicious VS Code extension or npm package." 
It's believed that the attackers are taking over maintainer accounts, likely through expired domain takeover or another account recovery path, to pull off the scheme. 
Once executed, the malware searches the infected computer for certain files like "postcss.config.mjs," "tailwind.config.js," "eslint.config.mjs," next.config.mjs," babel.config.js," and "app.js," and, if found, appends malicious JavaScript code to them. 
It also makes use of a Windows batch script to stealthily modify the last commit, while making it appear as if they were made by the original author. 
It's suspected that similar tools are being utilized to rewrite Git history for other operating systems like Linux and macOS. 
"The core tradecraft remains consistent across the campaign: threat actors plant obfuscated JavaScript loaders in legitimate repositories, conceal the code through whitespace padding or fake .woff2 font files, and trigger execution through developer tooling such as VS Code task files," Socket said. 
In the latest wave, the payload functions as a JavaScript malware loader that reaches out to blockchain infrastructure, including TRON, Aptos, and BNB Smart Chain services, to fetch an encrypted second-stage payload that unpacks to DEV#POPPER RAT and OmniStealer. 
This attack chain was detailed by eSentire in March 2026. 
"The threat actors use Git history rewriting, including force pushes and anti-dated commits to make malicious changes appear older and less suspicious," Zanki said. 
"This makes the GitHub landing page and visible commit history unreliable indicators of compromise; defenders should review repository activity logs, package release metadata, VS Code task configuration, and suspicious changes to configuration files." 
The development comes as JFrog uncovered a cluster of npm packages linked to Contagious Interview, some of which masqueraded as Rollup polyfill tools to enable remote access and data theft. 
Earlier this week, another set of npm packages and Go packages was identified as incorporating VS Code auto-run tasks to run JavaScript payloads disguised as fake font files, indicating tactical overlaps between Fake Font, TaskJacker, and PolinRider. 
Users who have installed these packages should treat the environment as compromised, rotate exposed secrets from a clean machine, remove affected versions and rebuild from a known good lockfile, and audit developer workstations and repositories for hidden execution paths or suspicious commits that have modified ".vscode/tasks.json," "config.js," "vite.config.js," and "eslint.config.js" files. 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias0.0%This article: 9.6%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias9.6%This article: 7.1%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic7.1%This article: 21.2%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic21.2%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias0.0%This article: 17.7%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias17.7%This article: 7.1%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect7.1%This article: 7.1%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion7.1%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 9.8%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias9.8%This article: 10.5%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias10.5%This article: 23.1%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias23.1%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 22.9%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias22.9%This article: 1.5%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect1.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 36.4%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority36.4%This article: 9.1%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma9.1%This article: 6.2%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope6.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 10.1%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization10.1%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 4.6%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion4.6%This article: 6.4%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question6.4%This article: 8.2%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)8.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 6.1%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof6.1%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 20.4%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)20.4%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 8.2%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote8.2%This article: 12.7%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection12.7%This article: 6.0%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice6.0%This article: 17.0%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination17.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

722 words analyzed.

Speakers

3speakers17%attributed speech599writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 100.0% coverageWriter's voice • 39 words • 0.0% coverageKarlo Zanki • 46 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 39 words • 100.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 31 words • 100.0% coverageWriter's voice • 49 words • 0.0% coverageWriter's voice • 38 words • 0.0% coverageWriter's voice • 33 words • 0.0% coverageOpenSourceMalware • 11 words • 100.0% coverageWriter's voice • 15 words • 100.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageSocket • 42 words • 100.0% coverageWriter's voice • 39 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageKarlo Zanki • 24 words • 100.0% coverageWriter's voice • 33 words • 100.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 51 words • 100.0% coverage
Selected voice

Socket

100%flagged-word coverage
42 attributed words34% of attributed speech94% writer coverage
0%50.0%100.0%Quote-first Misdirection+97.5 ptsWriter: 2.5%Socket: 100.0%100.0%Indoctrination-20.5 ptsWriter: 20.5%Socket: 0.0%0.0%Unattributed Quote-8.0 ptsWriter: 8.0%Socket: 0.0%0.0%Biased Writer Voice-7.2 ptsWriter: 7.2%Socket: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.