Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager
A supply chain attack has been identified where a malicious PHP package, visanduma/nova-two-factor, injects code into Laravel Nova extensions. This code queries Ethereum transactions to find C2 server IP addresses and then downloads a cross-platform credential stealer targeting browser accounts, crypto wallets, and developer credentials. There is currently no evidence of successful theft.
- Protocols
- Laravel Nova
- Chains
- Ethereum
- Confidence
- High
- First seen
- 21 Sep 2026, 09:00 UTC