logo

Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access

ID: 5f58805f-294f-5894-a32b-94d2573d0fe6

STIX ID: report--5f58805f-294f-5894-a32b-94d2573d0fe6

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A supply-chain campaign on Packagist involved packages published by user nhattuanbl that concealed an obfuscated PHP remote access trojan (RAT) inside helper.php (notably nhattuanbl/lara-helper and nhattuanbl/simple-queue), with nhattuanbl/lara-swagger pulling the malicious dependency. The RAT contacts helper.leuleu.net:2096, sends system reconnaissance, and accepts commands to run shells, capture screenshots, and transfer files; it is cross-platform, persists via Composer auto-discovery or file-scope includes, and retries C2 connections indefinitely. Teams should treat hosts with these packages as fully compromised, rotate secrets, remove the packages/helper.php, audit outbound traffic and transitive dependencies, and avoid dev-master constraints in production.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.