PolinRider Spreads Through Compromised GitHub Accounts and Packagist

2026-09-17 Socket

https://socket.dev/blog/polinrider-github-packagist

Thumbnail for PolinRider Spreads Through Compromised GitHub Accounts and Packagist

Socket identified PolinRider malware in four development versions of the Packagist package `visanduma/nova-two-factor`, tracing the changes to a compromised GitHub developer account that also accessed private repositories. The North Korea-linked operators rewrite Git history, conceal JavaScript in configuration or font-like files, abuse automatic VS Code tasks, and resolve command-and-control infrastructure through EtherHiding or NullReceiver. A newly observed PHP technique launches obfuscated JavaScript from `index.php` through `shell_exec`. Socket assesses Git-based developer compromise as the campaign's primary propagation model and cryptocurrency theft as its apparent main objective.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 515a53291d25d229e1f9fa72e66407e… 2026-09-17 2026-09-17
HASH 139ea03dcddf4aa810d55740be3cf6c… 2026-09-17 2026-09-17
HASH ccb187dc9de0cc7477c9817ae53365d… 2026-09-17 2026-09-17
HASH b7ede935d4979146b55f12b9eec7c83… 2026-09-17 2026-09-17
HASH 7d47c430e6e404dc2fa8b4837678d1c… 2026-09-17 2026-09-17
WALLET 0xa322E5f3D311D3080e6f0121063e9… 2026-09-17 2026-09-17
IPv4 193.247.144.38 2026-09-02 2026-09-17
IPv4 23.27.13.135 2026-09-02 2026-09-17
IPv4 166.88.73.46 2026-09-02 2026-09-17
IPv4 166.88.134.62 2026-07-28 2026-09-17

Related Actors

Related Reports

« Back