Malicious PHP Packages Found Hidden in Laravel Ecosystem
ID: 05b68fa4-10e2-5f8a-b640-ea55a7150d2f
STIX ID: report--05b68fa4-10e2-5f8a-b640-ea55a7150d2f
Feed Name: securityonline.info
Socket's Threat Research Team discovered a supply-chain attack on Packagist where the actor nhattuanbl published utility packages (nhattuanbl/lara-helper and nhattuanbl/simple-queue) containing an obfuscated PHP RAT and a third deceptive package (nhattuanbl/lara-swagger) that silently pulls the malicious dependency. The RAT runs within the Laravel application process, maintains persistence by spawning a detached background process, connects to a C2 (helper.leuleu.net:2096) and supports commands for system reconnaissance, remote command execution, file upload/download, screenshots, and credential exposure; developers are urged to audit composer.json and remove packages by nhattuanbl immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
