Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
ID: 170c8e2e-e593-5ada-aff5-03ed387fcc12
STIX ID: report--170c8e2e-e593-5ada-aff5-03ed387fcc12
Feed Name: The Hacker News
Security researchers discovered several malicious Packagist packages (notably nhattuanbl/lara-helper and nhattuanbl/simple-queue) that install a cross-platform PHP RAT into Laravel applications via Composer dependencies. The RAT connects to a C2 server, sends system reconnaissance, supports remote shell and PowerShell execution, file upload/download, screenshots, and persistent reconnection; it activates at application boot or via autoloading, running with the web app's permissions and exposing credentials and environment secrets. Users are advised to assume compromise, remove the packages, rotate secrets, and audit outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
