PolinRider shows how a software supply-chain operation can turn legitimate open source assets into a route for backdoors and credential theft, putting developer workstations at the center of the blast radius.