HomeSecurityMalicious Laravel Packages on Packagist Install RAT

Malicious Laravel Packages on Packagist Install RAT

Cybersecurity researchers have discovered malicious Laravel packages on Packagist that masquerade as legitimate tools and install a cross-platform remote access trojan (RAT) on Windows , macOS , and Linux systems . The “nhattuanbl/lara-swagger” package does not contain any malicious code directly, but installs the RAT via a dependency on “nhattuanbl/lara-helper” . This tactic exploits developers’ trust in the Composer dependency resolution system, making the attack particularly insidious and difficult to detect.

See also: North Koreans published 26 malicious npm packages for RAT distribution

Packagist 
Malicious Laravel Packages on Packagist Install RAT

According to Socket, the packages remain available for download from the official PHP package registry, which increases the risk of new infections. Both lara-helper and simple-queue contain a PHP named “src/helper.php”that uses advanced techniques to complicate static analysis. These include control flow obfuscation, encoding of domain names, commands, and file paths, as well as the use of random identifiers for variable and function names. These techniques make the malware almost invisible to traditional detection tools that rely on signatures or static code analysis.

Once loaded, the payload connects to a C2 server at helper.leuleu[.]net:2096 , sends system identification data and waits for commands, giving the attacker full remote access to the host. Communication is done over TCP using PHP ’s stream_socket_client() function , while the RAT collects extensive system information, including operating system information, installed software and network configuration. The RAT supports commands such as ping for a heartbeat every 60 seconds , info for sending system data, cmd and powershell for executing commands, screenshot for taking screenshots via the imagegrabscreen() function , as well as download and upload for managing files with full read, write and execute permissions.

See also: Trojanized gaming utilities spread Java-based RAT

Malicious Laravel Packages on Packagist Install RAT
Malicious Laravel Packages on Packagist Install RAT

To execute shell commands, the RAT checks the disable_functions and selects the first available method from: popen, proc_open, exec, shell_exec, system, passthru. This makes it highly resistant to common PHP that typically disable one or two of these functions. Although the C2 server is currently unresponsive, the RAT is configured to retry the connection attempt every 15 seconds in a persistent loop, maintaining its presence on the system and waiting for communication to be restored.

This attack is part of a broader pattern of malicious packages targeting the PHP ecosystem , and in particular the popular Laravel framework that holds over 70% of the PHP market . In September 2025 , over 800 malicious Laravel-related packages were identified on Packagist , injecting backdoors via similar dependency chains. Many of these targeted Vietnamese developer namespaces such as “nhattuanbl” , suggesting organized campaigns from Southeast Asia . In parallel, similar attacks have been recorded in other ecosystems, with over 1,200 malicious packages being removed from PyPI in 2025 .

In addition to the three packages mentioned, the threat actor behind the operation has published three other libraries (“nhattuanbl/lara-media”, “nhattuanbl/snooze” and “nhattuanbl/syslog”) that are clean, likely in an attempt to build credibility and trick users into installing the malware. This tactic, known as “namespace squatting”, has increased by 300% in 2025 according to data from Sonatype, making verifying the authenticity of packages critical for application security.

See also: Steaelite RAT: Data theft and ransomware in one tool

EDR

Users who have installed the packages are advised to immediately assume a breach and take drastic measures. First, they should remove the malicious packages by running composer remove nhattuanbl/lara-swagger nhattuanbl/lara-helper nhattuanbl/simple-queue , rotate all secrets accessible from the application environment, and check the outbound traffic to the C2 server in the network logs. In addition, it is recommended to completely regenerate API keys , change all passwords that were used to access the application, and check for unauthorized changes to system files.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS