You Run `go get` Every Day. North Korea Is Counting On It.
North Korean hackers are compromising Go and PHP packages through the PolinRider campaign β not through sophisticated exploits, but by exploiting a simple gap: Go and Packagist don’t require multi-factor authentication for publishers. While NPM and PyPI adapted after years of attacks, these registries chose convenience over security, outsourcing risk to every developer who runs `go get` or `composer install`.