Maintainer Takeovers Put the Trust Chain in Play

The break is not just poisoned packages. The attackers are taking over maintainer accounts and rewriting repository history, so cleanup can miss malicious changes that now look like part of the project’s own past. That shifts the target from the package itself to the trust chain around it, including the developer machine that built or installed it. Socket says PolinRider has now reached 162 malicious release artifacts across 108 unique packages, spanning npm, Packagist, Go modules, and a Chrome extension. The campaign uses compromised GitHub repositories, with some loaders hidden in configuration files and missed during cleanup. Packagist was added in the latest wave, including packages in the sevenspan namespace. If your teams install from public registries, the risk is broader than a bad version number. A compromised maintainer account can expose registry, source-code, cloud, and CI/CD credentials, and those secrets can outlive the package cleanup itself.

Part of the PlainSec briefing for 2026-07-06

Sources