PolinRider Spreads Through Compromised GitHub Accounts and Packagist
2026-09-17 • Socket •
Socket identified PolinRider malware in four development versions of the Packagist package `visanduma/nova-two-factor`, tracing the changes to a compromised GitHub developer account that also accessed private repositories. The North Korea-linked operators rewrite Git history, conceal JavaScript in configuration or font-like files, abuse automatic VS Code tasks, and resolve command-and-control infrastructure through EtherHiding or NullReceiver. A newly observed PHP technique launches obfuscated JavaScript from `index.php` through `shell_exec`. Socket assesses Git-based developer compromise as the campaign's primary propagation model and cryptocurrency theft as its apparent main objective.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 515a53291d25d229e1f9fa72e66407e… | 2026-09-17 | 2026-09-17 |
| HASH | 139ea03dcddf4aa810d55740be3cf6c… | 2026-09-17 | 2026-09-17 |
| HASH | ccb187dc9de0cc7477c9817ae53365d… | 2026-09-17 | 2026-09-17 |
| HASH | b7ede935d4979146b55f12b9eec7c83… | 2026-09-17 | 2026-09-17 |
| HASH | 7d47c430e6e404dc2fa8b4837678d1c… | 2026-09-17 | 2026-09-17 |
| WALLET | 0xa322E5f3D311D3080e6f0121063e9… | 2026-09-17 | 2026-09-17 |
| IPv4 | 193.247.144.38 | 2026-09-02 | 2026-09-17 |
| IPv4 | 23.27.13.135 | 2026-09-02 | 2026-09-17 |
| IPv4 | 166.88.73.46 | 2026-09-02 | 2026-09-17 |
| IPv4 | 166.88.134.62 | 2026-07-28 | 2026-09-17 |