logo

Malicious Laravel Packages Deploy PHP RAT, Grant Remote Access to Attackers

ID: 53346d99-e02b-54ee-bed1-e4bb6719b3bd

STIX ID: report--53346d99-e02b-54ee-bed1-e4bb6719b3bd

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Malicious Packagist packages published by the actor "nhattuanbl" (notably nhattuanbl/lara-helper and nhattuanbl/simple-queue) contain an obfuscated PHP RAT (src/helper.php) that relaunches as a background process, connects to a C2 at helper.leuleu.net:2096 using AES‑128‑CTR framing, exfiltrates host reconnaissance data, and provides remote shell, command execution, file upload/download, screenshots, and persistence; a benign-appearing package (nhattuanbl/lara-swagger) depends on lara-helper transitively enabling stealthy supply-chain installation—organizations should treat affected hosts as compromised, remove the packages and helper.php, delete the lock file, rotate secrets, and hunt for C2 connections and suspicious world-writable files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.