PolinRider Spreads Through Compromised GitHub Accounts and Packagist
PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft.
AI Analysis
Technical Summary
The PolinRider campaign involves compromise of developer GitHub accounts to inject malicious code into development versions of widely used packages, notably visanduma/nova-two-factor on Packagist. The operators leverage multiple ecosystems (npm, PyPI, Go modules, Packagist, Chrome extensions) and employ advanced techniques such as rewriting Git history, hiding payloads in configuration and font files, and triggering execution automatically via IDE tasks. Payload delivery is staged using dead-drop mechanisms like EtherHiding and NullReceiver. Infection primarily occurs through Git-based collaboration workflows rather than direct compromise of package registries. PHP projects are specifically targeted with obfuscated JavaScript executed via shell_exec calls. Attribution points to North Korean actors with a focus on cryptocurrency theft.
Potential Impact
This campaign enables attackers to distribute malicious code through trusted development workflows, potentially compromising software supply chains across multiple programming ecosystems. The injected code can execute obfuscated JavaScript in PHP projects, facilitating information theft and unauthorized actions. The use of compromised developer accounts and Git repositories increases the risk of widespread infection and stealthy persistence. The campaign's link to North Korean actors suggests a focus on cryptocurrency theft, posing financial and reputational risks to affected organizations and developers.
Mitigation Recommendations
No official patch or remediation is indicated. Since the infection vector is through compromised developer accounts and Git-based collaboration, mitigation should focus on securing developer accounts with strong authentication (e.g., multi-factor authentication), monitoring for unauthorized Git history rewriting, and auditing code changes in development branches. Developers should verify the integrity of dependencies, especially development versions, and be cautious of unexpected changes in Git repositories. Vendor or package registry advisories should be monitored for updates. There is no indication that direct package registry compromise is the primary vector, so registry-level mitigations are less relevant.
Indicators of Compromise
- ip: 166.88.134.62
- ip: 23.27.13.135
- ip: 166.88.73.46
- ip: 193.247.144.38
- hash: 7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9
- hash: b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3
- hash: ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395
- hash: 139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683
- hash: 515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Description
PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple ecosystems including npm, PyPI, Go modules, Packagist, and Chrome extensions. The operators use Git history rewriting, payload concealment in configuration files and font files, automatic execution through IDE tasks, and staged payload delivery via dead-drop mechanisms like EtherHiding and NullReceiver. Primary infection occurs through Git-based collaboration rather than direct package registry compromise, with PHP projects targeted using obfuscated JavaScript executed through shell_exec. The campaign appears linked to North Korean operators focused on cryptocurrency theft.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The PolinRider campaign involves compromise of developer GitHub accounts to inject malicious code into development versions of widely used packages, notably visanduma/nova-two-factor on Packagist. The operators leverage multiple ecosystems (npm, PyPI, Go modules, Packagist, Chrome extensions) and employ advanced techniques such as rewriting Git history, hiding payloads in configuration and font files, and triggering execution automatically via IDE tasks. Payload delivery is staged using dead-drop mechanisms like EtherHiding and NullReceiver. Infection primarily occurs through Git-based collaboration workflows rather than direct compromise of package registries. PHP projects are specifically targeted with obfuscated JavaScript executed via shell_exec calls. Attribution points to North Korean actors with a focus on cryptocurrency theft.
Potential Impact
This campaign enables attackers to distribute malicious code through trusted development workflows, potentially compromising software supply chains across multiple programming ecosystems. The injected code can execute obfuscated JavaScript in PHP projects, facilitating information theft and unauthorized actions. The use of compromised developer accounts and Git repositories increases the risk of widespread infection and stealthy persistence. The campaign's link to North Korean actors suggests a focus on cryptocurrency theft, posing financial and reputational risks to affected organizations and developers.
Defensive Guidance
No official patch or remediation is indicated. Since the infection vector is through compromised developer accounts and Git-based collaboration, mitigation should focus on securing developer accounts with strong authentication (e.g., multi-factor authentication), monitoring for unauthorized Git history rewriting, and auditing code changes in development branches. Developers should verify the integrity of dependencies, especially development versions, and be cautious of unexpected changes in Git repositories. Vendor or package registry advisories should be monitored for updates. There is no indication that direct package registry compromise is the primary vector, so registry-level mitigations are less relevant.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/polinrider-github-packagist"]
- Adversary
- PolinRider
- Pulse Id
- 6aad33cda70ed83efd0e0a73
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip166.88.134.62 | — | |
ip23.27.13.135 | — | |
ip166.88.73.46 | — | |
ip193.247.144.38 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9 | — | |
hashb7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3 | — | |
hashccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395 | — | |
hash139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683 | — | |
hash515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a | — |
Threat ID: 6aad47c755bf5e2cf51b60c8
Added to database: 09/18/2026, 14:16:39 UTC
Last enriched: 09/18/2026, 14:31:30 UTC
Last updated: 09/19/2026, 01:31:06 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.