logo

Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation

ID: 45e3f899-2cce-51a5-b810-af3c024f89df

STIX ID: report--45e3f899-2cce-51a5-b810-af3c024f89df

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-25

Date Updated: 2026-05-26

Author: Tushar Subhra Dutta

...
...

A supply-chain campaign has compromised over 700 PHP and Node.js repositories by adding postinstall scripts (and in some cases GitHub Actions steps) that silently download a Linux binary (fvbs.network) from the attacker-controlled GitHub account parikhrpreksha, save it as /tmp/.sshd, make it executable, and run it in the background; the campaign suppresses errors, disables TLS verification (curl -sk), and leverages branch-tracking dependencies and CI workflows to reach developer machines and automated build environments. Socket.dev flagged the behavior, Packagist removed affected packages, and recommended mitigation steps include auditing composer.json and package postinstall hooks, inspecting GitHub Actions workflows, and checking for dot-prefixed binaries in /tmp.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.