← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 17, 2026 · 15:33via Socket Security Blog

PolinRider Spreads Through Compromised GitHub Accounts and Packagist

Brief

Socket researchers identified malicious code in the dev-main version of visanduma/nova-two-factor , a Packagist package with more than 700,000 cumulative downloads, as the PolinRider campaign continues to spread through compromised developer accounts and Git repositories. The Socket Threat Research Team continues to track malicious activity associated with PolinRider.

In our July research post , we provided initial technical details about this persistent campaign, which distributes malware across npm, PyPI, Go modules, Packagist, and Chrome extensions. We also documented its expansion into the Packagist ecosystem. Among the latest affected projects is visanduma/nova-two-factor , a Packagist package with more than 700,000 cumulative downloads.

The malicious code is present in the unstable dev-* versions; no stable malicious release has been identified at the time of writing.

Read more on Socket Security Blog→