SlowMist
SlowMist|Sep 21, 2026 09:41
🚨 Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager SlowMist Security Team identified a PolinRider sample in a development branch of the #LaravelNova extension package visanduma/nova-two-factor, which has 700,000+ cumulative downloads. The malicious code is hidden in tailwind.config.js and executes during frontend builds. Instead of hardcoding C2 addresses, the loader queries #Ethereum transactions to dynamically resolve delivery server IPs, allowing the operator to switch servers without republishing the package. The final payload is a cross-platform credential stealer targeting: 🔹 Browser accounts, cookies, and credentials 🔹 Crypto wallet data and extension storage 🔹 Password managers 🔹 Git, GitHub CLI, and other developer credentials ⚠️ Developers and CI/build environments using affected versions should inspect composer.lock and tailwind.config.js, review build-time network activity, and treat successfully executed builds as compromised. Rotate exposed credentials and wallet keys from a clean environment. Full analysis👇 https://slowmist.medium.com/threat-intelligence-polinrider-poisons-nova-using-on-chain-transactions-as-a-c2-manager-5357a9d0222e
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads