Security researchers reported a PHP supply-chain compromise on Packagist in which packages published by the actor nhattuanbl embedded a remote access trojan (RAT) while masquerading as legitimate Laravel utility libraries. The RAT payload was identified in src/helper.php within nhattuanbl/lara-helper and nhattuanbl/simple-queue, while nhattuanbl/lara-swagger acted as a “clean” loader by declaring nhattuanbl/lara-helper as a hard Composer dependency, causing the malicious code to be pulled in during installation.
Once installed, the malware initiates outbound connectivity to the command-and-control endpoint helper[.]leuleu[.]net:2096, sends host profiling/reconnaissance data, and then awaits operator commands, enabling full remote control of the affected host. Reporting indicates the actor used reputation seeding by publishing additional clean packages under the same long-standing Packagist account (created in 2015) during a June–December 2024 publishing window, before releasing the RAT-bearing packages; researchers submitted takedown requests, but the packages were still available at the time of publication. Impacted Laravel/PHP applications may expose sensitive secrets available to the running process (e.g., .env environment variables, database credentials, and API keys).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
At publication, the command-and-control server was described as non-responsive, but the malware was noted to keep retrying connections indefinitely or at short intervals, meaning previously infected systems could reconnect if infrastructure returns.
After identifying the malicious packages, Socket submitted takedown requests to Packagist. At the time of reporting, the packages were still available.
Socket's Threat Research Team discovered and analyzed the malicious Packagist packages, linking the activity to the nhattuanbl publisher and documenting the embedded and transitive dependency delivery paths for the RAT.
When installed, the packages automatically execute the payload during Laravel boot or class autoload, launching a background process that profiles the host and connects to helper[.]leuleu[.]net:2096 over AES-128-CTR-encrypted TCP for remote command execution, file operations, and screenshots.
Later in that June–December 2024 publication sequence, the actor published packages including nhattuanbl/lara-helper and nhattuanbl/simple-queue with an obfuscated RAT in src/helper.php, while nhattuanbl/lara-swagger pulled the malware through a hard dependency on lara-helper.
A threat actor using the Packagist account name "nhattuanbl" published multiple PHP packages between June and December 2024, including several benign-looking libraries likely intended to build credibility with developers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.