PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Blog post from Socket
Socket researchers report that the PolinRider campaign inserted malware into development branches of visanduma/nova-two-factor, a Packagist package with more than 700,000 downloads, after compromising the Visanduma GitHub organization through a developer account in mid-June 2026; no malicious stable release had been identified. The campaign primarily exploits Git-based development workflows rather than package registries alone, using force-pushed history, concealed JavaScript in configuration or font-like files, IDE tasks that execute when repositories open, and staged command-and-control delivery methods to infect developer systems and potentially spread into private repositories. Researchers also identified a newer PHP-focused technique in which obfuscated JavaScript embedded in index.php is launched via shell_exec. PolinRider’s full scope is difficult to assess because public repository searches cannot reveal private projects, removed malicious commits, or systems infected before cleanup, while its payloads are associated chiefly with cryptocurrency theft and may also expose credentials and source code. Recommended mitigations include avoiding affected development branches, pinning dependencies to verified versions, auditing Git history and automated execution paths, investigating potentially exposed hosts, rotating credentials, and strengthening repository and IDE security controls.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 1 | 451 | 99 | 43 | -80% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.