CoinScoopCrypto news from around the world

PolinRider campaign exploits Laravel Nova package for credential theft

SlowMist ·

The PolinRider campaign has compromised a popular Laravel Nova extension package, visanduma/nova-two-factor, which has over 700,000 downloads. The malicious code uses Ethereum transactions to dynamically retrieve command-and-control server IP addresses, allowing attackers to update infrastructure without re-poisoning the package. The payload functions as a credential stealer targeting browser data, encrypted wallets, and developer credentials. SlowMist's MistEye system has issued risk alerts regarding this threat.

  • $ETH
  • #슬로우미스트
  • #해킹
  • #이더리움
  • #보안
  • #악성코드

Summaries are written by AI from the original article. Not investment advice.

More from this day