Related Threat Clusters
-
Malicious Packagist Themes Exploit iPhones for Spyware and Crypto Theft
Thirteen malicious Composer theme packages on Packagist have been identified, targeting unpatched iPhones by injecting JavaScript into Vietnamese movie and comic streaming sites. The injected code facilitates mobile ad…
5 articles · Updated September 1, 2026 -
Critical Command Injection Vulnerabilities in Composer's Perforce Driver
Two command injection vulnerabilities, CVE-2026-40176 and CVE-2026-40261, have been identified in Composer's Perforce VCS driver, allowing attackers to execute arbitrary commands on user systems. CVE-2026-40176,…
5 articles · Updated April 15, 2026 -
Supply Chain Attack Compromises Laravel Lang Packages with Credential Stealer
On May 22, 2026, a supply chain attack targeted Laravel Lang localization packages, compromising 233 versions across four repositories. Attackers exploited GitHub's version tagging system to redirect legitimate tags to…
17 articles · Updated May 23, 2026 -
Packagist Issues Urgent Update After GitHub Actions Token Leak
A recent change in GitHub's token format has led to a security vulnerability in Composer, exposing sensitive GitHub authentication tokens in CI/CD logs. This flaw affects PHP developers globally, as the outdated…
2 articles · Updated May 14, 2026 -
OphimCMS Supply Chain Attack Delivers Trojanized jQuery via Malicious Packagist Themes
A supply chain attack has compromised OphimCMS, a Vietnamese-language Laravel CMS, through six malicious Composer packages published on Packagist. These packages, disguised as legitimate themes, contain trojanized…
2 articles · Updated March 17, 2026 -
New Malware Blocking Features Implemented in Composer 2.10 and Private Packagist
On June 26, 2026, Private Packagist announced enhancements to its malware blocking capabilities for Composer users, particularly those using version 2.10. The updates prevent the installation of flagged malware…
3 articles · Updated June 26, 2026
Recent Intelligence Reports
- Hackers Use Malicious Website Themes to Steal Crypto Wallet Seeds From iPhones — Cybersecuritynews · September 1, 2026
- 13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds — Gbhackers · September 1, 2026
- Packagist is now protected by Aikido Intel and other updates to the PHP registry — Aikido.Dev · June 26, 2026
- Laravel Lang Supply Chain Advisory — Snyk · May 23, 2026
- Laravel Lang Packages Hijacked to Deploy Credential-Stealing Malware — Ground.News · May 23, 2026
- Hackers Compromise Laravel — Gbhackers · May 23, 2026
- Hackers Compromised 233 Versions of Laravel — Cybersecuritynews · May 23, 2026
- Packagist Warns: Update Composer Now After GitHub Actions Token Leak — Gbhackers · May 14, 2026