PolinRider Spreads Through Compromised GitHub Accounts and Packagist

Reported 18 Sep 2026 by otx · Severity: medium

PolinRider operators compromised a GitHub account to insert malicious code into development versions of visanduma/nova-two-factor, a Packagist package with over 700,000 downloads. The campaign spreads through compromised developer accounts and Git repositories across multiple eco