Home / Companies / Socket / Blog / Post Details
Content Deep Dive

PolinRider Spreads Through Compromised GitHub Accounts and Packagist

Blog post from Socket

Post Details
Company
Date Published
Author
Karlo Zanki
Word Count
1,349
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket researchers report that the PolinRider campaign inserted malware into development branches of visanduma/nova-two-factor, a Packagist package with more than 700,000 downloads, after compromising the Visanduma GitHub organization through a developer account in mid-June 2026; no malicious stable release had been identified. The campaign primarily exploits Git-based development workflows rather than package registries alone, using force-pushed history, concealed JavaScript in configuration or font-like files, IDE tasks that execute when repositories open, and staged command-and-control delivery methods to infect developer systems and potentially spread into private repositories. Researchers also identified a newer PHP-focused technique in which obfuscated JavaScript embedded in index.php is launched via shell_exec. PolinRider’s full scope is difficult to assess because public repository searches cannot reveal private projects, removed malicious commits, or systems infected before cleanup, while its payloads are associated chiefly with cryptocurrency theft and may also expose credentials and source code. Recommended mitigations include avoiding affected development branches, pinning dependencies to verified versions, auditing Git history and automated execution paths, investigating potentially exposed hosts, rotating credentials, and strengthening repository and IDE security controls.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 451 99 43 -80%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.