logo

Malicious PHP Packages Found Hidden in Laravel Ecosystem

ID: 05b68fa4-10e2-5f8a-b640-ea55a7150d2f

STIX ID: report--05b68fa4-10e2-5f8a-b640-ea55a7150d2f

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Socket's Threat Research Team discovered a supply-chain attack on Packagist where the actor nhattuanbl published utility packages (nhattuanbl/lara-helper and nhattuanbl/simple-queue) containing an obfuscated PHP RAT and a third deceptive package (nhattuanbl/lara-swagger) that silently pulls the malicious dependency. The RAT runs within the Laravel application process, maintains persistence by spawning a detached background process, connects to a C2 (helper.leuleu.net:2096) and supports commands for system reconnaissance, remote command execution, file upload/download, screenshots, and credential exposure; developers are urged to audit composer.json and remove packages by nhattuanbl immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.