Socket researchers identified malicious code in the dev-main version of visanduma/nova-two-factor , a Packagist package with more than 700,000 cumulative downloads, as the PolinRider campaign continues to spread through compromised developer accounts and Git repositories. The Socket Threat Research Team continues to track malicious activity associated with PolinRider. In our July research post , we provided initial technical details about this persistent campaign, which distributes malware across npm, PyPI, Go modules, Packagist, and Chrome extensions.