DeTracker Security Feed

$98.3M lost this week $92.4B lost in 30 days $93.3B lost this year

Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager

A supply chain attack has been identified where a malicious PHP package, visanduma/nova-two-factor, injects code into Laravel Nova extensions. This code queries Ethereum transactions to find C2 server IP addresses and then downloads a cross-platform credential stealer targeting browser accounts, crypto wallets, and developer credentials. There is currently no evidence of successful theft.

Source: SlowMist Medium (opens in a new tab)

#LaravelNova