CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Malicious Laravel Packages Deploy Cross-Platform RAT via Packagist

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Malicious PHP packages on Packagist, disguised as Laravel utilities, deploy a cross-platform remote access trojan (RAT) affecting Windows, macOS, and Linux systems. The packages 'nhattuanbl/lara-helper' and 'nhattuanbl/simple-queue' contain obfuscated PHP code that connects to a C2 server, enabling full remote access to compromised hosts. The RAT supports various commands, including system reconnaissance, shell execution, and file operations. The packages remain available for download, and users are advised to assume compromise, remove the packages, and audit their systems.

Timeline

  1. 04.03.2026 11:37 1 articles · 2h ago

    Malicious Laravel Packages Deploy Cross-Platform RAT via Packagist

    Cybersecurity researchers have identified malicious PHP packages on Packagist that deploy a cross-platform RAT affecting Windows, macOS, and Linux systems. The packages 'nhattuanbl/lara-helper' and 'nhattuanbl/simple-queue' contain obfuscated PHP code that connects to a C2 server, enabling full remote access to compromised hosts. The RAT supports various commands, including system reconnaissance, shell execution, and file operations. The packages remain available for download, and users are advised to assume compromise, remove the packages, and audit their systems.

    Show sources

Information Snippets