"Evolution of Web3 in Cloud Supply Chain Attacks" published by PaloaltoNetworks. #NPM, #AlluringPisces, #EtherHiding, #PolinRider, #NullReceiver https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks

"Evolution of Web3 in Cloud Supply Chain Attacks" published by PaloaltoNetworks. #NPM, #AlluringPisces, #EtherHiding, #PolinRider, #NullReceiver https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks
DPRK malware now finds its C2 on the blockchain - one transaction rotates it, no domain to block. https://intel.threadlinqs.com/threat/TL-2026-3023 #ThreatIntel #ChainDrop #PolinRider #NullReceiver
"How to Investigate a GitHub Repo's Real History" published by OpenSourceMalware. #GitHub, #VSCode, #PolinRider https://opensourcemalware.com/blog/how-to-investigate-a-github-repos-real-history
"PolinRider Switches to Ethereum C2 in 30+ Repositories" published by SafeDep. #GitHub, #PolinRider https://safedep.io/polinrider-ethereum-c2-github-repositories/
"Their GitHub Repo Was Compromised. The Trail Led to North Korea." published by tarunrd77. #GitHub, #VSCode, #PolinRider, #NullReceiver https://medium.com/@tarunrd77/their-github-repo-was-compromised-the-trail-led-to-north-korea-6d332abbdedf
"PolinRider is A/B Testing its Way Past Your Detections" published by OpenSourceMalware. #GitHub, #VSCode, #PolinRider, #NullReceiver https://opensourcemalware.com/blog/polinrider-is-a-b-testing-its-way-past-your-detections
Lazarus turned the Terraform Registry into a malware drop - a typosquatted Docker provider hides a Go RAT. https://intel.threadlinqs.com/threat/TL-2026-2635 #ThreatIntel #Graphalgo #Contagious #PolinRider
"PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager" published by Slowmist. #PolinRider https://slowmist.medium.com/threat-intelligence-polinrider-poisons-nova-using-on-chain-transactions-as-a-c2-manager-5357a9d0222e
"威胁情报|PolinRider 投毒 Nova,链上交易充当 C2 管理器" published by Slowmist. #PolinRider https://mp.weixin.qq.com/s?__biz=MzU4ODQ3NTM2OA%3D%3D&mid=2247506155&idx=1&sn=4383482c02a55bc2ebc837f8956d1147&chksm=fddea66ccaa92f7afeccf60bd4a15c6c31f8ff6131a44caf160411659d5ed2e10fa8c26037b3
npm's trusted-publishing pipeline just proved provenance can lie: DPRK slipped a loader past it. https://intel.threadlinqs.com/threat/TL-2026-2588 #ThreatIntel #GHAPPIER #PolinRider #BeaverTail
"GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign" published by CloudSEK. #GitHub, #NPM, #PolinRider, #NullReceiver, #GHAPPIER https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack
"August 2026 Threat Trend Report on APT Groups" published by Ahnlab. #Trend, #DreamJob, #Kimsuky, #Lazarus, #FamousChollima, #JasperSleet, #PolinRider, #CVE202668820 https://asec.ahnlab.com/en/95478
"PolinRider Spreads Through Compromised GitHub Accounts and Packagist" published by Socket. #GitHub, #EtherHiding, #VSCode, #PolinRider, #NullReceiver https://socket.dev/blog/polinrider-github-packagist
"Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack" published by MalBeacon. #PyPI, #OtterCandy, #PolinRider https://blog.deception.pro/blog/hok-dprk-polinrider-sep-2026
"Malicious code executed on clone between 2026-08-29 and 2026-09-02" published by BindsNET. #VSCode, #PolinRider, #BindsNET https://github.com/BindsNET/bindsnet/security/advisories/GHSA-6f2q-w3r8-xxhj