Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT and Enables Remote Access

A security incident has been identified involving a supply chain attack targeting the PHP developer community via Packagist, the official repository for PHP and Laravel packages.

A security incident has been identified involving a supply chain attack targeting the PHP developer community via Packagist, the official repository for PHP and Laravel packages.

The attack involved the publication of several packages by the threat actor nhattuanbl , disguised as legitimate Laravel utility libraries, which contained a remote access trojan (RAT). These packages provided attackers with silent and persistent control over systems that installed them.

The threat actor released six packages under the same author name between June and December 2024. Of these, three were clean, while nhattuanbl/lara-helper and nhattuanbl/simple-queue contained malicious code embedded in a file named src/helper.php . Additionally, nhattuanbl/lara-swagger indirectly included the malicious payload by setting a dependency on lara-helper .

Once installed, the payload connects to a command-and-control (C2) server at helper[.]leuleu[.]net on port 2096, transmitting system profiles and awaiting operator commands for remote control.

These packages provided attackers with silent and persistent control over systems that installed them.
Danielle Frost · Thehackingpost

The campaign impacts any Laravel application that installed these packages, allowing the RAT to access environment variables, database credentials, and API keys stored in .env files. The threat is cross-platform, affecting Windows, macOS, and Linux systems.

The RAT continues attempts to contact its C2 server every 15 seconds, retaining the potential for reactivation if redirected to a new host.

The helper.php file is obfuscated and uses various techniques for stealth, including control flow disruption and string encoding. The RAT activates differently based on the package, either through Laravel's auto-discovery mechanism or immediate execution upon autoload.

Advertisement

Once activated, the RAT runs as a background process, encrypted communication is facilitated using AES-128-CTR with a hardcoded key, and it executes commands received from the C2 server.

Consider any systems using nhattuanbl/lara-helper , nhattuanbl/simple-queue , or nhattuanbl/lara-swagger as compromised. Rotate all credentials accessible from the application environment. Remove the malicious packages and audit file permissions, particularly for chmod 0777 files. Delete the lock file at {sys_get_temp_dir}/wvIjjnDMRaomchPprDBzzVSpzh61RCar.lock . Review and monitor outbound network traffic to helper[.]leuleu[.]net:2096 and audit all dependencies. Avoid using dev-master constraints in production environments to ensure version integrity.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories