logo

Hackers Hide Linux Malware in SSH-Like Package Filename

ID: acb1bc0f-42e1-5c41-9dc3-91245a3fca51

STIX ID: report--acb1bc0f-42e1-5c41-9dc3-91245a3fca51

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-25

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Researchers uncovered a coordinated supply-chain campaign where attackers modified upstream GitHub repositories to add malicious post-install package.json scripts that download a Linux binary to /tmp/.sshd and execute it, affecting multiple Packagist packages (notably Laravel starter kits) and leveraging npm lifecycle scripts and CI workflows to maximize impact; Socket reported and had the packages removed, and IOCs include the GitHub account parikhpreyash4 and a release URL for the payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.