High Frontend infra hack Source: SlowMist Medium

Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager

A supply chain attack has been identified where a malicious PHP package, visanduma/nova-two-factor, injects code into Laravel Nova extensions. This code queries Ethereum transactions to find C2 server IP addresses and then downloads a cross-platform credential stealer targeting browser accounts, crypto wallets, and developer credentials. There is currently no evidence of successful theft.

Protocols
Laravel Nova
Chains
Ethereum
Confidence
High
First seen
21 Sep 2026, 09:00 UTC

On-chain references

Read the original report ↗ (opens in a new tab)