Skip to main content

PolinRider Spreads Through Compromised GitHub Accounts and Packagist

0
Medium
Published: 09/18/2026 (09/18/2026, 12:51:25 UTC)
Source: AlienVault OTX General

Description

PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 14:31:30 UTC

Technical Analysis

The PolinRider campaign involves compromise of developer GitHub accounts to inject malicious code into development versions of widely used packages, notably visanduma/nova-two-factor on Packagist. The operators leverage multiple ecosystems (npm, PyPI, Go modules, Packagist, Chrome extensions) and employ advanced techniques such as rewriting Git history, hiding payloads in configuration and font files, and triggering execution automatically via IDE tasks. Payload delivery is staged using dead-drop mechanisms like EtherHiding and NullReceiver. Infection primarily occurs through Git-based collaboration workflows rather than direct compromise of package registries. PHP projects are specifically targeted with obfuscated JavaScript executed via shell_exec calls. Attribution points to North Korean actors with a focus on cryptocurrency theft.

Potential Impact

This campaign enables attackers to distribute malicious code through trusted development workflows, potentially compromising software supply chains across multiple programming ecosystems. The injected code can execute obfuscated JavaScript in PHP projects, facilitating information theft and unauthorized actions. The use of compromised developer accounts and Git repositories increases the risk of widespread infection and stealthy persistence. The campaign's link to North Korean actors suggests a focus on cryptocurrency theft, posing financial and reputational risks to affected organizations and developers.

Defensive Guidance

No official patch or remediation is indicated. Since the infection vector is through compromised developer accounts and Git-based collaboration, mitigation should focus on securing developer accounts with strong authentication (e.g., multi-factor authentication), monitoring for unauthorized Git history rewriting, and auditing code changes in development branches. Developers should verify the integrity of dependencies, especially development versions, and be cautious of unexpected changes in Git repositories. Vendor or package registry advisories should be monitored for updates. There is no indication that direct package registry compromise is the primary vector, so registry-level mitigations are less relevant.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/polinrider-github-packagist"]
Adversary
PolinRider
Pulse Id
6aad33cda70ed83efd0e0a73

Indicators of Compromise

Ip

ValueDescriptionCopy
ip166.88.134.62
ip23.27.13.135
ip166.88.73.46
ip193.247.144.38

Hash

ValueDescriptionCopy
hash7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9
hashb7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3
hashccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395
hash139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683
hash515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a

Threat ID: 6aad47c755bf5e2cf51b60c8

Added to database: 09/18/2026, 14:16:39 UTC

Last enriched: 09/18/2026, 14:31:30 UTC

Last updated: 09/19/2026, 01:31:06 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses