nhattuanbl is a threat actor identifier associated with a software supply-chain campaign targeting PHP and Laravel developers through malicious Packagist packages. The actor published multiple packages under the same author name, including benign-looking packages likely intended to build credibility, while distributing at least two packages that embedded an obfuscated remote access trojan and a third package that installed the trojan transitively through a hard dependency. The operation targeted Laravel application environments by abusing Composer package installation and framework auto-loading behavior. In one package, the payload executed automatically through Laravel service-provider auto-discovery during application boot; in another, execution occurred when the package was autoloaded. The malware then spawned a detached background process, maintained persistence within the application context, performed host reconnaissance, and established encrypted command-and-control communications. Reported operator capabilities included remote command execution, file upload and download, screenshot capture, and collection of host and environment information. Because the malware ran with the same privileges as the compromised web application, it could access application secrets and environment variables, including credentials and API keys commonly stored in Laravel deployments. The payload was described as cross-platform, functioning on Windows, macOS, and Linux. It used substantial obfuscation, including control-flow flattening, escaped strings, and randomized identifiers, along with encrypted C2 messaging. The malware continuously retried outbound connections, enabling ongoing post-compromise access if infrastructure became reachable again. Observed behavior is consistent with software dependency compromise, reconnaissance, persistence, defense evasion, exfiltration, and post-exploitation activity. No high-confidence attribution to a nation state or a broader named intrusion set is currently available. The available evidence supports tracking nhattuanbl as an actor name tied to a malicious open-source package distribution campaign against the PHP/Laravel ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a software supply-chain campaign via Packagist by publishing PHP/Laravel packages that embedded (or pulled in) an obfuscated cross-platform RAT, enabling persistent remote control of systems that installed the packages.
Software supply-chain activity via malicious Packagist/Composer packages that deliver an obfuscated PHP RAT. The RAT is executed via Laravel service-provider auto-discovery or PHP autoload side effects, self-launches as a background process, performs host reconnaissance, and provides full remote access (shell execution, file upload/download, screenshot) over an AES-encrypted raw TCP C2 channel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.