216.73.217.22

Malicious Packagist Packages Disguised as Laravel Utilities Deploy Encrypted RAT

· Published 04/03/2026 10:55 · Modified 04/03/2026 11:15

Export JSON

Essential information

Published
04/03/2026 10:55
Modified
04/03/2026 11:15
Tags
2026-03-04 dependency-chain laravel packagist php rat
Related entities
2 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 others

Description

A remote access trojan () has been discovered in multiple packages published by the threat actor nhattuanbl. The malicious packages, disguised as utilities, install an encrypted via Composer dependencies. The payload connects to a C2 server, sends system reconnaissance data, and awaits commands, granting full remote access to the host. The uses obfuscation techniques to resist analysis and employs a self-launch mechanism. It communicates with the C2 server using encrypted JSON messages and supports various commands for system control and data exfiltration. The attack vector leverages dependency chains, with clean-looking packages pulling in malicious ones. Affected systems should be treated as compromised, with recommendations provided for mitigation and prevention.

External references