logo

Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux

ID: 170c8e2e-e593-5ada-aff5-03ed387fcc12

STIX ID: report--170c8e2e-e593-5ada-aff5-03ed387fcc12

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Security researchers discovered several malicious Packagist packages (notably nhattuanbl/lara-helper and nhattuanbl/simple-queue) that install a cross-platform PHP RAT into Laravel applications via Composer dependencies. The RAT connects to a C2 server, sends system reconnaissance, supports remote shell and PowerShell execution, file upload/download, screenshots, and persistent reconnection; it activates at application boot or via autoloading, running with the web app's permissions and exposing credentials and environment secrets. Users are advised to assume compromise, remove the packages, rotate secrets, and audit outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.