supply-chain
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
High
Summary
A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux binary designed for remote code execution, exploiting a gap in developer security practices. Packagist has since removed the malicious packages, but the incident highlights the risks associated with dependency management and the importance of thorough scanning.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
