supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux binary designed for remote code execution, exploiting a gap in developer security practices. Packa… The Hacker News · May 23, 2026 High supply-chainphpcomposer