SlowMist said its security team found a PolinRider malware sample in a development branch of the Laravel Nova package visanduma/nova-two-factor, a package with more than 700,000 cumulative downloads. According to the team, the malicious code was hidden in tailwind.config.js and ran during the front-end build process. Instead of hardcoding a command-and-control, or C2, server address, the loader queried Ethereum transactions to dynamically resolve the IP address of the delivery server. SlowMist said that design let the attacker switch servers without republishing the package. The final payload was described as a cross-platform credential stealer targeting browser accounts, cookies, credentials, cryptocurrency wallet data, password managers, and developer secrets tied to Git and GitHub CLI. The team urged users on affected versions to inspect related files, review network activity during builds, and rotate any exposed credentials and wallet keys.
SlowMist said on X that its security team discovered a PolinRider malware sample in a development branch of the Laravel Nova package visanduma/nova-two-factor. The package has recorded more than 700,000 cumulative downloads.
Malicious code hidden in a build file
According to SlowMist, the malicious code was concealed in tailwind.config.js and executed during the front-end build process.
Ethereum transactions used to manage C2 infrastructure
The loader did not hardcode the command-and-control, or C2, server address. Instead, it queried Ethereum transactions to dynamically resolve the IP address of the delivery server. SlowMist said this allowed the attacker to change servers without republishing the package.
Final payload targeted credentials and wallet data
The final payload was a cross-platform credential stealer. SlowMist said the targets included browser accounts, cookies, credentials, cryptocurrency wallet data, password managers, and developer credentials such as Git and GitHub CLI secrets.
What SlowMist advised users to do
The team advised users running affected versions to inspect related files, review network activity during the build process, and rotate exposed credentials and wallet keys.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.