Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
ID: d8b08a0c-af32-5dfb-950e-cf5be1e1fb12
STIX ID: report--d8b08a0c-af32-5dfb-950e-cf5be1e1fb12
Feed Name: securityonline.info
Socket researchers uncovered a coordinated supply-chain campaign that hid malicious postinstall JavaScript hooks inside package.json files and GitHub Actions workflows of several PHP Composer packages; the script downloads a Linux binary named gvfsd-network to /tmp/.sshd and runs it as a background backdoor. The attack targets repositories bundling JavaScript build tooling—especially starter kits where npm install runs at the project root—posing a risk to developer machines and CI pipelines; Packagist removed the flagged packages and maintainers reverted commits, and defenders are advised to audit package.json scripts and pin branch-tracking dependencies to specific commits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
