PolinRider Campaign Spreads Through Compromised GitHub Accounts and Packagist

· Original article ↗

Summary

Socket researchers found PolinRider malware in development versions of a Packagist package and describe how the campaign compromises Git repositories, infects developer environments, and delivers infostealers.

Key points

  • Malicious code was found in dev-* versions of visanduma/nova-two-factor, a package with more than 700,000 cumulative downloads; no malicious stable release was identified.
  • The Visanduma GitHub organization’s repositories appear compromised since mid-June 2026 through the LaHiRu developer account; activity in private repositories limits the known scope.
  • PolinRider rewrites Git history, conceals JavaScript in configuration or font files, and can execute code when repositories are opened in compatible IDEs or built.
  • A newly observed PHP variant places obfuscated JavaScript in index.php and launches it using shell_exec.
  • The malware resolves command-and-control infrastructure through dead-drop methods, including EtherHiding and NullReceiver, then downloads later-stage infostealers.
  • Execution may leave developer workstations or CI environments compromised even after repository cleanup; the campaign’s full impact is unknown.
  • Socket advises avoiding affected development branches, auditing repository history and execution paths, investigating systems where code ran, rebuilding when integrity is uncertain, and rotating accessible credentials.

Article Details

Attack Vectors
  • Operators use compromised developer accounts to insert malicious code into Git repositories and force-push rewritten history.
  • Malicious JavaScript is concealed in configuration files or files presented as .woff2 fonts. Patched configuration can execute during builds or tests.
  • Some repositories use .vscode/tasks.json with "runOn": "folderOpen" to execute code when opened in a VS Code–compatible IDE.
  • In a recently identified variation, obfuscated JavaScript inserted into index.php is launched through PHP's shell_exec function.
  • Initial code resolves C2 infrastructure through a dead-drop mechanism and downloads later-stage infostealer payloads.
  • Malicious source code in visanduma/nova-two-factor is available through affected development branches on Packagist; no stable malicious release had been identified at the time of writing.
Defensive Notes
  • Avoid visanduma/nova-two-factor development branches until the repository is confirmed clean; pin dependencies to a reviewed, known-good commit or stable release.
  • Audit repository history and account activity, including force-pushes, branch-protection changes, reflogs, workflows, tokens, sessions, commits, collaborators, and private-repository activity.
  • Inspect .vscode/tasks.json, build and test configuration, .woff2 files, and shell_exec calls for unexpected execution paths.
  • Treat execution from an affected repository as a potential workstation compromise. Isolate and investigate affected hosts, and reimage them if integrity cannot be established.
  • Revoke and replace credentials accessible to affected users or processes, and restrict force-pushes and automatic execution of untrusted repository tasks.

Indicators of compromise

TypeIndicatorContext
IPV4166[.]88[.]134[.]62Resolved C2 IP address listed in the article's indicators.
IPV4166[.]88[.]73[.]46Resolved C2 IP address listed in the article's indicators.
IPV4193[.]247[.]144[.]38Resolved C2 IP address listed in the article's indicators.
IPV423[.]27[.]13[.]135Resolved C2 IP address listed in the article's indicators.
SHA256139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683Hash of a malicious tailwind.config.js payload file.
SHA256515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531aHash of a malicious tailwind.config.js payload file.
SHA2567d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9Hash of a malicious tailwind.config.js payload file.
SHA256b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3Hash of a malicious tailwind.config.js payload file.
SHA256ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395Hash of a malicious tailwind.config.js payload file.

MITRE ATT&CK

Vendors

Products

Countries

Related Articles