PolinRider 投毒 Nova,链上交易充当 C2 管理器
2026-09-21 • Slowmist • PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager •
SlowMist linked malicious development branches of the Packagist package visanduma/nova-two-factor to PolinRider and found a loader concealed after 507 spaces in tailwind.config.js. Laravel Mix execution queries Ethereum transactions to derive rotating C2 IP addresses, retrieves Node.js and Python stages, and ultimately deploys a cross-platform credential stealer. The payload targets browser credentials and cookies, cryptocurrency wallets, password managers, development tokens, and operating-system credential stores on Windows, macOS, and Linux. SlowMist recovered the remote payloads for static analysis but states it has no victim-side evidence confirming successful theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 166.88.134.75 | 2026-09-21 | 2026-09-21 |
| HASH | 515a53291d25d229e1f9fa72e66407e… | 2026-09-17 | 2026-09-21 |
| IPv4 | 193.247.144.38 | 2026-09-02 | 2026-09-21 |
| IPv4 | 23.27.13.135 | 2026-09-02 | 2026-09-21 |
| IPv4 | 166.88.73.46 | 2026-09-02 | 2026-09-21 |
| WALLET | 0xa322e5f3d311d3080e6f0121063e9… | 2026-08-02 | 2026-09-21 |
| IPv4 | 166.88.134.62 | 2026-07-28 | 2026-09-21 |