SlowMist|Sep 21, 2026 09:41
🚨 Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager
SlowMist Security Team identified a PolinRider sample in a development branch of the #LaravelNova extension package visanduma/nova-two-factor, which has 700,000+ cumulative downloads.
The malicious code is hidden in tailwind.config.js and executes during frontend builds. Instead of hardcoding C2 addresses, the loader queries #Ethereum transactions to dynamically resolve delivery server IPs, allowing the operator to switch servers without republishing the package.
The final payload is a cross-platform credential stealer targeting:
🔹 Browser accounts, cookies, and credentials
🔹 Crypto wallet data and extension storage
🔹 Password managers
🔹 Git, GitHub CLI, and other developer credentials
⚠️ Developers and CI/build environments using affected versions should inspect composer.lock and tailwind.config.js, review build-time network activity, and treat successfully executed builds as compromised. Rotate exposed credentials and wallet keys from a clean environment.
Full analysis👇
https://slowmist.medium.com/threat-intelligence-polinrider-poisons-nova-using-on-chain-transactions-as-a-c2-manager-5357a9d0222e
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink