logo

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

ID: c9fb56ed-a491-5965-be7d-1a7aa447710f

STIX ID: report--c9fb56ed-a491-5965-be7d-1a7aa447710f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-23

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

A coordinated supply-chain attack affected eight Packagist packages by adding package.json postinstall scripts that download a Linux binary from a GitHub Releases URL, save it to /tmp/.sshd, chmod it executable, and run it in the background; the payload or installer was also found across hundreds of GitHub files and placed in some GitHub Actions workflows, suggesting broader distribution and multiple execution paths. The second-stage binary is unavailable, but the installer enables remote code execution during installs or CI builds and has been removed from Packagist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.