logo

Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages

ID: d8b08a0c-af32-5dfb-950e-cf5be1e1fb12

STIX ID: report--d8b08a0c-af32-5dfb-950e-cf5be1e1fb12

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Ddos

...
...

Socket researchers uncovered a coordinated supply-chain campaign that hid malicious postinstall JavaScript hooks inside package.json files and GitHub Actions workflows of several PHP Composer packages; the script downloads a Linux binary named gvfsd-network to /tmp/.sshd and runs it as a background backdoor. The attack targets repositories bundling JavaScript build tooling—especially starter kits where npm install runs at the project root—posing a risk to developer machines and CI pipelines; Packagist removed the flagged packages and maintainers reverted commits, and defenders are advised to audit package.json scripts and pin branch-tracking dependencies to specific commits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.