PolinRider Spreads Through Compromised GitHub Accounts and Packagist
AI Summary
The PolinRider campaign continues to spread through compromised GitHub accounts and Packagist, leveraging Git-based infrastructure to inject malicious code into development versions of popular packages. Researchers identified malicious activity in the dev branches of the visanduma/nova-two-factor Packagist package, which has over 700,000 downloads. The attackers use compromised developer accounts to insert obfuscated JavaScript into configuration files and PHP entry points, enabling automatic execution upon repository access or build processes. The campaign employs staged payload delivery via dead-drop resolvers and maintains persistence by rewriting Git history and exploiting IDE integrations such as VS Code tasks.
AI-extracted · verify before operational use
Indicators of Compromise 18 extracted
| Type | Value | Detail |
|---|---|---|
| Package | visanduma/nova-two-factor@dev-nova4support | Details → |
| Package | visanduma/nova-two-factor@dev-main | Details → |
| Package | visanduma/nova-two-factor@dev-using-inertia | Details → |
| Package | visanduma/nova-two-factor@dev-nova5 | Details → |
| GitHub User | LaHiRu | Details → |
| GitHub Repo | visanduma/nova-two-factor | Details → |
| IP | 193[.]247[.]144[.]38 | Details → |
| IP | 166[.]88[.]73[.]46 | Details → |
| IP | 166[.]88[.]134[.]62 | Details → |
| IP | 23[.]27[.]13[.]135 | Details → |
| SHA-256 | 7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9 | Details → |
| SHA-256 | b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3 | Details → |
| SHA-256 | ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395 | Details → |
| SHA-256 | 139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683 | Details → |
| SHA-256 | 515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a | Details → |
| Filename | tailwind.config.js | Details → |
| Registry User | visanduma | Details → |
| GitHub User | visanduma | Details → |