Date: 09/23/2026
Severity: High
Summary
PolinRider campaign, which compromises GitHub developer accounts and repositories to spread malware through software development workflows and package ecosystems. The campaign uses (Supply Chain Attack) Git history rewriting, malicious configuration files, VS Code auto-execution, payload concealment, and EtherHiding/NullReceiver for staged C2 delivery. A compromised Packagist package with more than 700,000 downloads contained malicious code in development branches, while later stages delivered infostealers targeting credentials harvesting, source code theft, and cryptocurrency-related information.
Indicators of Compromise (IOC) List
IP Address | 193.247.144.38 166.88.73.46 166.88.134.62 23.27.13.135 |
Hash | 7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9
b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3
ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395
139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683
515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("166.88.73.46","23.27.13.135","193.247.144.38","166.88.134.62") or srcipaddress IN ("166.88.73.46","23.27.13.135","193.247.144.38","166.88.134.62") |
Detection Query 2 : | sha256hash IN ("139ea03dcddf4aa810d55740be3cf6c92ce7a9f3cbcbbb35440e25b769a87683","b7ede935d4979146b55f12b9eec7c83b61962b478f5dc9b8db251e539ec2abd3","515a53291d25d229e1f9fa72e66407e1cfd7e77c91478400b24d5185af68531a","ccb187dc9de0cc7477c9817ae53365d273e121407c0305f863e2ab67c35d6395","7d47c430e6e404dc2fa8b4837678d1cbdb4d0aeacec9b405655cab79d54a2ad9")
|
Reference:
https://socket.dev/blog/polinrider-github-packagist