PolinRider Campaign Spreads Through Compromised GitHub Accounts and Packagist

Summary
Socket researchers found PolinRider malware in development versions of a Packagist package and describe how the campaign compromises Git repositories, infects developer environments, and delivers infostealers.
Key points
- Malicious code was found in dev-* versions of visanduma/nova-two-factor, a package with more than 700,000 cumulative downloads; no malicious stable release was identified.
- The Visanduma GitHub organization’s repositories appear compromised since mid-June 2026 through the LaHiRu developer account; activity in private repositories limits the known scope.
- PolinRider rewrites Git history, conceals JavaScript in configuration or font files, and can execute code when repositories are opened in compatible IDEs or built.
- A newly observed PHP variant places obfuscated JavaScript in index.php and launches it using shell_exec.
- The malware resolves command-and-control infrastructure through dead-drop methods, including EtherHiding and NullReceiver, then downloads later-stage infostealers.
- Execution may leave developer workstations or CI environments compromised even after repository cleanup; the campaign’s full impact is unknown.
- Socket advises avoiding affected development branches, auditing repository history and execution paths, investigating systems where code ran, rebuilding when integrity is uncertain, and rotating accessible credentials.
Article Details
- Attack Vectors
- Operators use compromised developer accounts to insert malicious code into Git repositories and force-push rewritten history.
- Malicious JavaScript is concealed in configuration files or files presented as .woff2 fonts. Patched configuration can execute during builds or tests.
- Some repositories use .vscode/tasks.json with "runOn": "folderOpen" to execute code when opened in a VS Code–compatible IDE.
- In a recently identified variation, obfuscated JavaScript inserted into index.php is launched through PHP's shell_exec function.
- Initial code resolves C2 infrastructure through a dead-drop mechanism and downloads later-stage infostealer payloads.
- Malicious source code in visanduma/nova-two-factor is available through affected development branches on Packagist; no stable malicious release had been identified at the time of writing.
- Defensive Notes
- Avoid visanduma/nova-two-factor development branches until the repository is confirmed clean; pin dependencies to a reviewed, known-good commit or stable release.
- Audit repository history and account activity, including force-pushes, branch-protection changes, reflogs, workflows, tokens, sessions, commits, collaborators, and private-repository activity.
- Inspect .vscode/tasks.json, build and test configuration, .woff2 files, and shell_exec calls for unexpected execution paths.
- Treat execution from an affected repository as a potential workstation compromise. Isolate and investigate affected hosts, and reimage them if integrity cannot be established.
- Revoke and replace credentials accessible to affected users or processes, and restrict force-pushes and automatic execution of untrusted repository tasks.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 166[.]88[.]134[.]62 | Resolved C2 IP address listed in the article's indicators. |
| IPV4 | 166[.]88[.]73[.]46 | Resolved C2 IP address listed in the article's indicators. |
| IPV4 | 193[.]247[.]144[.]38 | Resolved C2 IP address listed in the article's indicators. |
| IPV4 | 23[.]27[.]13[.]135 | Resolved C2 IP address listed in the article's indicators. |
| SHA256 | 139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683 | Hash of a malicious tailwind.config.js payload file. |
| SHA256 | 515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a | Hash of a malicious tailwind.config.js payload file. |
| SHA256 | 7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9 | Hash of a malicious tailwind.config.js payload file. |
| SHA256 | b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3 | Hash of a malicious tailwind.config.js payload file. |
| SHA256 | ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395 | Hash of a malicious tailwind.config.js payload file. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe campaign uses heavily obfuscated JavaScript and conceals malicious JavaScript in configuration files or files presented as fonts.T1059.007 · JavaScriptObfuscated JavaScript inserted into index.php is launched through PHP's shell_exec function.T1078 · Valid AccountsOperators use compromised developer accounts to introduce malicious changes into repositories.T1102.001 · Dead Drop ResolverInitial code uses a dead-drop mechanism to resolve C2 infrastructure before retrieving later-stage payloads.T1105 · Ingress Tool TransferInitial code downloads later-stage infostealer payloads from resolved servers.T1195.001 · Compromise Software Dependencies and Development ToolsOperators plant malicious code in source repositories, including the repository behind affected Packagist development versions.
Vendors
Products
Gitdownloads, as the PolinRider campaign continues to spread through compromised developer accounts and Git repositories.GitHubAnalysis of the Visanduma GitHub organization indicates that its repositories have been compromised since mid-June 2026. The malicious changes were introduced through the LaHiRu developer account. Public contributionNode.jsbuild or test configuration; executable content in .woff2 files; and shell_exec calls that launch Node.js or decoded commands.PackagistSocket researchers identified malicious code in the dev-main version of visanduma/nova-two-factor, a Packagist package with more than 700,000 cumulative downloads, as the PolinRider campaign continues to spread throughPHPNew PHP Execution Technique#visanduma/nova-two-factorSocket researchers identified malicious code in the dev-main version of visanduma/nova-two-factor, a Packagist package with more than 700,000 cumulative downloads, as the PolinRider campaign continues to spread throughVS Code"runOn": "folderOpen" in .vscode/tasks.json, triggering code when a developer opens the repository in a VS Code–compatible IDE.