Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
ID: c9fb56ed-a491-5965-be7d-1a7aa447710f
STIX ID: report--c9fb56ed-a491-5965-be7d-1a7aa447710f
Feed Name: The Hacker News
A coordinated supply-chain attack affected eight Packagist packages by adding package.json postinstall scripts that download a Linux binary from a GitHub Releases URL, save it to /tmp/.sshd, chmod it executable, and run it in the background; the payload or installer was also found across hundreds of GitHub files and placed in some GitHub Actions workflows, suggesting broader distribution and multiple execution paths. The second-stage binary is unavailable, but the installer enables remote code execution during installs or CI builds and has been removed from Packagist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
