Skip to content

Security incident: PolinRider malware found in this repo #591

@CharlieEriksen

Description

@CharlieEriksen

This repository has been compromised with malware (PolinRider).

Image

Direct link to affected code

What happened

A malicious actor gained access to this repository and injected malware into the codebase. The malware family has been identified as PolinRider, which is known to steal credentials, secrets, and environment variables from infected machines.

Who is affected

If you have run the latest version of this code, you should consider your machine and any tokens, secrets, or credentials present on it to be compromised. This includes but is not limited to:

  • API keys and access tokens
  • SSH keys
  • Environment variables
  • Cloud credentials (AWS, GCP, Azure, etc.)
  • NPM, PyPI, or other registry tokens

Immediate actions to take

  1. Rotate all credentials that were present on any machine that ran the affected code
  2. Revoke and reissue any tokens, API keys, or secrets
  3. Audit access logs for any of your services for suspicious activity
  4. Scan your machine for further signs of compromise

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions