Malicious Laravel Packages Deploy PHP RAT, Grant Remote Access to Attackers
ID: 53346d99-e02b-54ee-bed1-e4bb6719b3bd
STIX ID: report--53346d99-e02b-54ee-bed1-e4bb6719b3bd
Feed Name: GBHackers
Malicious Packagist packages published by the actor "nhattuanbl" (notably nhattuanbl/lara-helper and nhattuanbl/simple-queue) contain an obfuscated PHP RAT (src/helper.php) that relaunches as a background process, connects to a C2 at helper.leuleu.net:2096 using AES‑128‑CTR framing, exfiltrates host reconnaissance data, and provides remote shell, command execution, file upload/download, screenshots, and persistence; a benign-appearing package (nhattuanbl/lara-swagger) depends on lara-helper transitively enabling stealthy supply-chain installation—organizations should treat affected hosts as compromised, remove the packages and helper.php, delete the lock file, rotate secrets, and hunt for C2 connections and suspicious world-writable files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
