Hackers Hide Linux Payload Under SSH-Like Filename During Package Installation
ID: 45e3f899-2cce-51a5-b810-af3c024f89df
STIX ID: report--45e3f899-2cce-51a5-b810-af3c024f89df
Feed Name: cybersecurityNews.com
A supply-chain campaign has compromised over 700 PHP and Node.js repositories by adding postinstall scripts (and in some cases GitHub Actions steps) that silently download a Linux binary (fvbs.network) from the attacker-controlled GitHub account parikhrpreksha, save it as /tmp/.sshd, make it executable, and run it in the background; the campaign suppresses errors, disables TLS verification (curl -sk), and leverages branch-tracking dependencies and CI workflows to reach developer machines and automated build environments. Socket.dev flagged the behavior, Packagist removed affected packages, and recommended mitigation steps include auditing composer.json and package postinstall hooks, inspecting GitHub Actions workflows, and checking for dot-prefixed binaries in /tmp.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
