PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager

2026-09-21 Slowmist

https://slowmist.medium.com/threat-intelligence-polinrider-poisons-nova-using-on-chain-transactions-as-a-c2-manager-5357a9d0222e

Thumbnail for PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager

PolinRider compromised development branches of the Packagist package `visanduma/nova-two-factor` by hiding an executable loader inside `tailwind.config.js`. The loader derives rotating C2 addresses from Ethereum transaction recipient fields, then downloads Node.js and Python components over plaintext HTTP. Its final cross-platform stealer targets browser sessions, cryptocurrency wallets, password managers, operating-system credential stores, and developer credentials such as GitHub tokens and environment variables. SlowMist reconstructed the complete delivery chain but found no victim evidence confirming successful theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 166.88.134.75 2026-09-21 2026-09-21
HASH 515a53291d25d229e1f9fa72e66407e… 2026-09-17 2026-09-21
IPv4 193.247.144.38 2026-09-02 2026-09-21
IPv4 23.27.13.135 2026-09-02 2026-09-21
IPv4 166.88.73.46 2026-09-02 2026-09-21
WALLET 0xa322e5f3d311d3080e6f0121063e9… 2026-08-02 2026-09-21
IPv4 166.88.134.62 2026-07-28 2026-09-21

Related Actors

Related Reports

« Back