PolinRider Spreads Through Compromised GitHub Accounts and Packagist

    Date: 09/23/2026

    Severity: High

    Summary

    PolinRider campaign, which compromises GitHub developer accounts and repositories to spread malware through software development workflows and package ecosystems. The campaign uses (Supply Chain Attack) Git history rewriting, malicious configuration files, VS Code auto-execution, payload concealment, and EtherHiding/NullReceiver for staged C2 delivery. A compromised Packagist package with more than 700,000 downloads contained malicious code in development branches, while later stages delivered infostealers targeting credentials harvesting, source code theft, and cryptocurrency-related information.

    Indicators of Compromise (IOC) List

    IP Address

    193.247.144.38

    166.88.73.46

    166.88.134.62

    23.27.13.135

    Hash

    7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9

    b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3

    ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395

    139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683

    515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("166.88.73.46","23.27.13.135","193.247.144.38","166.88.134.62") or srcipaddress IN ("166.88.73.46","23.27.13.135","193.247.144.38","166.88.134.62")

    Detection Query 2 :

    sha256hash IN ("139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683","b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3","515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a","ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395","7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9")

    Reference:    

    https://socket.dev/blog/polinrider-github-packagist                                                 


    Tags

    MalwareGitHubEtherHidingInfostealercryptocurrencySupply chain attackCredential Harvesting

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags