PolinRider

discovered 2026-07-28

PolinRider loader family. Blockchain dead-drop C2 loader injected into npm bundles and developer-owned GitHub repositories by infected developer machines, with forged commit metadata. Generations: Tron -> BSC -> Aptos payload-in-calldata (astro.config.mjs, @joyfill), and from 2026-06-23 an Ethereum address-encoded dead drop with two operator wallets (0x33ff3eda...9891, 256-block heartbeat, global.o markers; 0xa322E5f3...Ef1a, 1000-block heartbeat, global.i="A..." markers, 'helloipbot!!' suffix). The Ethereum generation is tied to earlier samples by shared C2 198.105.127.210 and 166.88.134.62, AS149440 Evoxt hosting, the global._p_t guard, and global.r/m/___dirname and _H/_H2/_t_s/_t_u globals. Stage chain from 45.137.198.133: Node stealer (process.env to /snv, CI and sandbox hostname blocklist) -> Python infostealer build 260924 (browser credentials, 153 extension IDs, git credentials, /u/e and /u/f exfiltration, Telegram sendDocument fallback). XOR keys: YU7m{rE/>|==b>#~ (/0/body), q4FZkxX{!h,Sr3=@ (/0x/cls), y-p_>d$0B&@^1aQk (/0x/ls).

Objective

Steal developer secrets, browser credentials, and wallet data, and spread through repositories and packages owned by infected developers.

Packages

Indicators

Techniques

Read the full analysis →