North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
2026-07-04T13:24:08Z•0cca69d9c556ccedc3e95a7bc46e6d6afdeacb38fe20c4d5c6ef8fd4b08e4970
active-exploitationarbitrary-code-executionchrome-extensioncredential-theftembedded-iotespionagekernel-exploitkuberneteslocal-privilege-escalationnpmpackagistphishingransomwareremote-code-executionsupply-chain
What happened
Multiple high-impact threats and widespread vulnerabilities were reported: North Korea-linked actors (PolinRider/Contagious Interview) published 108 malicious packages and browser extensions across npm, Packagist, Go, and Chrome stores (supply-chain compromise). A local privilege-escalation Linux kernel flaw (Bad Epoll, CVE-2026-46242) enables unprivileged users to gain root (affects Linux and Android). runZero disclosed seven flaws in the ubiquitous FatFs library used in embedded devices (cameras, drones, controllers, hardware wallets). Microsoft SharePoint RCE (CVE-2026-45659, CVSS 8.8) was/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0cca69d9c556ccedc3e95a7bc46e6d6afdeacb38fe20c4d5c6ef8fd4b08e4970
- Enrichment time
- 2026-07-04T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.