PolinRider campaign exploits Laravel Nova package for credential theft
The PolinRider campaign has compromised a popular Laravel Nova extension package, visanduma/nova-two-factor, which has over 700,000 downloads. The malicious code uses Ethereum transactions to dynamically retrieve command-and-control server IP addresses, allowing attackers to update infrastructure without re-poisoning the package. The payload functions as a credential stealer targeting browser data, encrypted wallets, and developer credentials. SlowMist's MistEye system has issued risk alerts regarding this threat.
Summaries are written by AI from the original article. Not investment advice.