PolinRider Malware Uses Ethereum C2 to Steal Wallet Data
The PolinRider malware campaign compromised development versions of the Laravel Nova package visanduma/nova-two-factor, which had more than 700,000 cumulative downloads. Malicious code was hidden in tailwind.config.js and executed when affected projects ran frontend builds.
The PolinRider malware uses Ethereum transactions as a command-and-control mechanism. Attackers encode changing server IP addresses in transaction recipient fields, allowing them to update delivery infrastructure without republishing the infected package. The loader then downloads additional components over unencrypted HTTP, including a remote-control tool, reinfection loader and Python-based payload.
The final credential stealer targets Chrome, Edge, Brave, Firefox and other browsers, cryptocurrency wallets, password managers, GitHub credentials, environment variables and system credential stores. It can collect data linked to MetaMask, Phantom, Ledger Live, Trezor Suite, Solana wallets and other applications before packaging and uploading the information.
SlowMist said the analysis confirms a complete supply-chain attack chain, but it has not found victim evidence proving successful theft. The main risk affects developer machines, build containers and CI runners. Traders and crypto users should treat executed builds as potentially compromised, rotate wallet keys and passwords, revoke developer tokens, review account activity and block the listed indicators of compromise.
Bearish
The immediate market impact is likely limited because the incident targets developer environments rather than exchanges or blockchain infrastructure, and no confirmed victim losses were reported. However, the security implications are negative for crypto sentiment. The stealer specifically targets wallet files, browser sessions, seed-related data, password managers and GitHub credentials, creating a risk of unauthorized wallet access, token theft and follow-on attacks.
In the short term, traders may increase scrutiny of wallet security, move funds to freshly generated wallets and reduce exposure to projects linked to compromised development environments. If confirmed theft or large wallet movements emerge, affected assets could face sharp, event-driven selling and volatility, similar to previous supply-chain compromises and wallet-drainer incidents.
The longer-term effect is likely to be increased demand for dependency scanning, reproducible builds, hardware wallets, key rotation and CI isolation. The use of Ethereum transactions as a C2 manager also highlights how public blockchains can be abused for resilient infrastructure, but it does not by itself weaken Ethereum’s network or support a sustained ETH price move. Overall, the event is bearish for crypto-security confidence, while its direct broad-market price effect remains modest unless stolen funds are traced to major wallets or exchanges.