news.mlab.sh
Back to the feed
supply-chain

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

High
Image: The Hacker News
Summary

A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux binary designed for remote code execution, exploiting a gap in developer security practices. Packagist has since removed the malicious packages, but the incident highlights the risks associated with dependency management and the importance of thorough scanning.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.