Image for Article: Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux

Article Details

Title
Article: Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
Impact Score
5 / 10
AI Summary (Processed Content)

Malicious PHP packages on the Packagist registry are distributing a cross-platform remote access trojan (RAT) that targets Laravel applications. The packages, including "nhattuanbl/lara-helper" and "nhattuanbl/simple-queue," use obfuscation to hide a payload that connects to a command-and-control server, providing attackers with full remote shell access, file manipulation, and system reconnaissance. The RAT is persistent and runs with the web application's permissions, exposing sensitive data like credentials. Users are advised to remove the packages, rotate all secrets, and audit network traffic.

Original URL
https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html
Source Feed
The Hacker News
Published Date
2026-03-04 09:37
Fetched Date
2026-03-04 13:38
Processed Date
2026-03-04 14:01
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content