Threat reportSupply ChainTL-2026-0190

Fake Laravel Packages on Packagist Deploy Cross-Platform RAT via Supply Chain Compromise

highDORMANT

Fake Laravel Packages on Packagist Deploy Cross-Platform RAT (TL-2026-0190), also tracked as Packagist Laravel RAT Campaign, is a high-severity supply-chain compromise scored CVSS 8.8, first published 2026-03-07. It has no confirmed attribution, affects nhattuanbl (Packagist) lara-helper, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 17 indicators of compromise.

CVSS
8.8/10High
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-0190

Threat ID
TL-2026-0190
Also known as
Packagist Laravel RAT Campaign
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
DORMANT
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
technology, software-development, saas, e-commerce, financial, healthcare
Target regions
Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in Fake Laravel Packages on Packagist Deploy Cross-Platform RAT

Malware and tooling: Custom PHP RAT (AES-128-CTR encrypted TCP)

How Fake Laravel Packages on Packagist Deploy Cross-Platform RAT works

Threat actor nhattuanbl published six PHP packages to Packagist impersonating Laravel utilities, with three packages (lara-helper, simple-queue, lara-swagger) embedding or transitively pulling in an obfuscated Remote Access Trojan. The RAT connects to a C2 server at helper.leuleu.net:2096 using AES-128-CTR encrypted TCP, granting attackers full remote shell access, file read/write, screenshot capture, and credential theft from compromised Laravel application environments.

A supply chain attack targeting the PHP developer ecosystem was discovered by Socket.dev researcher Kush Pandya in March 2026. The threat actor operating under the Packagist username 'nhattuanbl' (email: nhattuanbl.woop@gmail.com, account registered December 2015) published six packages between June and December 2024 that masqueraded as legitimate Laravel utility libraries. Three of the six packages served as clean credibility builders: nhattuanbl/lara-media, nhattuanbl/snooze, and nhattuanbl/syslog. Two packages — nhattuanbl/lara-helper (37 installs) and nhattuanbl/simple-queue (29 installs) — contained an identical malicious payload embedded in src/helper.php. A sixth package, nhattuanbl/lara-swagger (49 installs), contained no direct malicious code but declared nhattuanbl/lara-helper as a hard Composer dependency, ensuring the RAT was installed transitively whenever developers required the swagger utility. The malicious file src/helper.php is 27,340 bytes delivered as a single continuous line after the opening <?php tag. It employs three distinct obfuscation layers: (1) control flow shattered into hundreds of randomized goto jumps with meaningless labels like tc0pE and IlaiV, (2) every string literal including domain names, command names, and file paths encoded using hexadecimal or octal escape sequences, and (3) all variable and function names replaced with randomly generated strings. Once loaded via Composer autoloading, the payload connects to a command-and-control server at helper.leuleu.net on port 2096 using PHP's stream_socket_client() function over raw TCP. All traffic between the RAT and C2 is encrypted using AES-128-CTR with a hardcoded 16-byte key (esCAmxUoJkIjTV0n). The RAT transmits a full system profile including hostname, OS version, user permissions, and a machine unique ID, then enters a persistent command loop retrying the connection every 15 seconds if disconnected. The RAT probes disable_functions and selects the first available execution method from: popen, proc_open, exec, shell_exec, system, passthru. Supported C2 commands include: ping (heartbeat every 60 seconds), info (system reconnaissance), cmd (shell command execution), powershell (PowerShell command execution), run (background shell execution), screenshot (using imagegrabscreen()), download (arbitrary file reading), upload (file writing with rwx permissions), and stop (socket termination). The C2 domain helper.leuleu.net resolves to 173.230.142.118, hosted on Linode (Akamai Technologies) infrastructure in the United States. The parent domain leuleu.net is protected by Cloudflare DNS. At the time of public disclosure, the C2 server was non-responsive, though the RAT's persistent retry loop means compromised hosts will reconnect automatically if the server comes back online. Any Laravel application that installed these packages has a persistent RAT running within the same PHP process as the web application, with access to environment variables, database credentials, API keys, and secrets stored in .env files. The RAT is cross-platform, functioning on Windows, macOS, and Linux systems. The packages required ext-mongodb, ext-openssl, deerdama/console-zoo-laravel, and ircmaxell/random-lib as dependencies. The malicious packages were flagged by Aikido security scanner and remain documented on Packagist with malware warnings.

---

**Revalidated on 2026-03-12**

Eight days after initial public disclosure, the nhattuanbl supply chain attack remains an active and unresolved threat. Despite Socket.dev's takedown request submitted on March 3 and broad media coverage on March 4, the three weaponized packages (lara-helper, simple-queue, lara-swagger) remain listed on Packagist.org. The only mitigation is an Aikido security scanner flag displaying a prominent 'Versions of this package have been flagged as malware by Aikido' warning on each package's Packagist page -- but the packages have not been delisted or made uninstallable. No official Composer security advisory has been issued through Packagist's advisory database. The Jamaica CIRT elevated this to a national-level advisory (JMCIRT-SA-2026-007) with a Critical rating, recommending organizations treat any system that installed the affected packages as fully compromised, remove all traces, rotate all credentials, and rebuild from trusted sources. The SecuriTricks attack report confirmed the SHA-256 hash of the malicious payload (a493ce9509c5180e997a04cab2006a48202afbb8edfa15149a4521067191ead7) and provided comprehensive MITRE ATT&CK mapping across 8 techniques. The OffSeq threat intelligence radar, which last updated this threat entry on March 11, 2026, continues to classify it as an active campaign with no documented resolution. While the C2 server at helper.leuleu.net:2096 was non-responsive at the time of reporting, the RAT's persistent 15-second retry loop means any C2 reactivation would instantly re-establish attacker access. The affected regions span globally including the United States, Germany, United Kingdom, France, Canada, Australia, Netherlands, Japan, India, and Brazil. The Packagist ecosystem's slow response to removing confirmed malware packages -- over a week after public disclosure -- highlights a significant gap in the PHP supply chain security posture compared to npm and PyPI, which typically delist malicious packages within hours of verified reports.

MITRE ATT&CK techniques used in TL-2026-0190

collection

T1005 Data from Local System; T1113 Screen Capture

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

discovery

T1033 System Owner/User Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter

command-and-control

T1095 Non-Application Layer Protocol; T1573 Encrypted Channel

initial-access

T1195 Supply Chain Compromise

privilege-escalation

T1546 Event Triggered Execution

credential-access

T1552 Unsecured Credentials

impact

T1565 Data Manipulation

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities

Affected products and versions in Fake Laravel Packages on Packagist Deploy Cross-Platform RAT

  • nhattuanbl (Packagist) — lara-helper
    Vulnerable versions: 5.2; 5.2.1; 5.3; 5.4; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.4.6
  • nhattuanbl (Packagist) — simple-queue
    Vulnerable versions: all
  • nhattuanbl (Packagist) — lara-swagger
    Vulnerable versions: 1.4; 2.0; dev-master

Remediation for Fake Laravel Packages on Packagist Deploy Cross-Platform RAT

Immediate actions

  • Audit all Composer dependencies for nhattuanbl/lara-helper, nhattuanbl/simple-queue, and nhattuanbl/lara-swagger
  • Remove any identified malicious packages immediately: composer remove nhattuanbl/lara-helper nhattuanbl/simple-queue nhattuanbl/lara-swagger
  • Block outbound connections to helper.leuleu.net and 173.230.142.118 at firewall/proxy level
  • Treat any host that installed affected packages as fully compromised
  • Rotate all secrets accessible from the application environment including database passwords, API keys, and .env values

Workarounds

  • Use composer audit to check for known malicious packages
  • Review composer.lock for any references to nhattuanbl vendor packages
  • Search for src/helper.php files containing obfuscated goto-based control flow

Longer-term hardening

  • Implement Composer package integrity verification and lockfile auditing in CI/CD pipelines
  • Deploy software composition analysis (SCA) tools to detect malicious dependencies
  • Enforce package allowlisting for critical applications
  • Monitor outbound TCP connections from PHP processes for anomalous C2 communication
  • Implement network segmentation to limit lateral movement from compromised developer environments

Weaknesses (CWE) in Fake Laravel Packages on Packagist Deploy Cross-Platform RAT

CWE-506, CWE-829, CWE-912

Timeline of Fake Laravel Packages on Packagist Deploy Cross-Platform RAT

  • Packagist account nhattuanbl registered, establishing long-term legitimacy for future supply chain attack
  • Threat actor begins publishing packages to Packagist under nhattuanbl, including clean decoy packages (lara-media, snooze, syslog) to build credibility
  • nhattuanbl/lara-swagger v2.0 published with hard dependency on lara-helper, creating transitive malware delivery chain
  • nhattuanbl/lara-helper v5.5.1 published — latest version containing RAT payload in src/helper.php
  • Last Packagist auto-sync for nhattuanbl packages recorded
  • OffSeq Threat Radar adds campaign to live threat intelligence tracking database, categorized as active campaign with medium severity [Source: https://radar.offseq.com/threat/malicious-packagist-packages-disguised-as-laravel--5cae3aaa]
  • SecuriTricks publishes attack report confirming SHA-256 hash a493ce9509c5180e997a04cab2006a48202afbb8edfa15149a4521067191ead7 and mapping attack to 8 MITRE ATT&CK techniques [Source: https://securitricks.com/attackreports/malicious-packagist-packages-disguised-as-laravel-utilities-deploy-encrypted-rat]
  • Aikido security scanner flags nhattuanbl/lara-helper and nhattuanbl/lara-swagger with prominent ''flagged as malware'' warnings on their Packagist package pages [Source: https://packagist.org/packages/nhattuanbl/lara-helper]
  • Jamaica Cyber Incident Response Team (CIRT) issues advisory JMCIRT-SA-2026-007 rating the threat as Critical, recommending immediate package removal, credential rotation, and network monitoring for C2 connections [Source: https://cirt.gov.jm/advisory/fake-laravel-packages-packagist-deploy-rat-windows-macos-and-linux]
  • Aikido security scanner flags affected package versions as malware on Packagist
  • The Hacker News, CybersecurityNews, GBHackers, SC Media, and others publish reports on the supply chain attack
  • Socket.dev researcher Kush Pandya publishes analysis identifying malicious RAT payload in nhattuanbl packages
  • C2 server at helper.leuleu.net:2096 confirmed non-responsive at time of public reporting, though RAT retry loop remains active
  • OffSeq Threat Radar last modified entry confirms threat status remains Active with no official resolution or package removal documented as of this date [Source: https://radar.offseq.com/threat/malicious-packagist-packages-disguised-as-laravel--5cae3aaa]
  • Revalidation confirms packages still listed on Packagist.org with Aikido malware flags but not removed; no Composer security advisory issued; C2 server remains non-responsive but RAT retry loop persists on any compromised hosts [Source: https://packagist.org/packages/nhattuanbl/lara-helper]
  • As of 2026-05-29, the nhattuanbl Packagist/Laravel RAT campaign is dormant: its C2 (helper.leuleu.net:2096) was already non-responsive at Socket's Mar 3 disclosure and the malicious lara-helper/simple-queue are no longer on the actor's Packagist page. But it is not fully resolved, as lara-swagger reportedly stayed listed and installed hosts retain the persistent RAT until remediated.

Sources cited for Fake Laravel Packages on Packagist Deploy Cross-Platform RAT

Detection coverage for TL-2026-0190

As of 2026-03-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0190 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats