Back to Intel

Intel Node

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

lowmalware2026-05-23T16:07:51+00:00source excerpt
malwarelinux

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Socket said.

Read Original Source