Threat reportSupply ChainTL-2026-0190
Fake Laravel Packages on Packagist Deploy Cross-Platform RAT via Supply Chain Compromise
Fake Laravel Packages on Packagist Deploy Cross-Platform RAT (TL-2026-0190), also tracked as Packagist Laravel RAT Campaign, is a high-severity supply-chain compromise scored CVSS 8.8, first published 2026-03-07. It has no confirmed attribution, affects nhattuanbl (Packagist) lara-helper, maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 17 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-0190
- Threat ID
- TL-2026-0190
- Also known as
- Packagist Laravel RAT Campaign
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- DORMANT
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, saas, e-commerce, financial, healthcare
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Fake Laravel Packages on Packagist Deploy Cross-Platform RAT
Malware and tooling: Custom PHP RAT (AES-128-CTR encrypted TCP)
How Fake Laravel Packages on Packagist Deploy Cross-Platform RAT works
Threat actor nhattuanbl published six PHP packages to Packagist impersonating Laravel utilities, with three packages (lara-helper, simple-queue, lara-swagger) embedding or transitively pulling in an obfuscated Remote Access Trojan. The RAT connects to a C2 server at helper.leuleu.net:2096 using AES-128-CTR encrypted TCP, granting attackers full remote shell access, file read/write, screenshot capture, and credential theft from compromised Laravel application environments.
A supply chain attack targeting the PHP developer ecosystem was discovered by Socket.dev researcher Kush Pandya in March 2026. The threat actor operating under the Packagist username 'nhattuanbl' (email: nhattuanbl.woop@gmail.com, account registered December 2015) published six packages between June and December 2024 that masqueraded as legitimate Laravel utility libraries. Three of the six packages served as clean credibility builders: nhattuanbl/lara-media, nhattuanbl/snooze, and nhattuanbl/syslog. Two packages — nhattuanbl/lara-helper (37 installs) and nhattuanbl/simple-queue (29 installs) — contained an identical malicious payload embedded in src/helper.php. A sixth package, nhattuanbl/lara-swagger (49 installs), contained no direct malicious code but declared nhattuanbl/lara-helper as a hard Composer dependency, ensuring the RAT was installed transitively whenever developers required the swagger utility. The malicious file src/helper.php is 27,340 bytes delivered as a single continuous line after the opening <?php tag. It employs three distinct obfuscation layers: (1) control flow shattered into hundreds of randomized goto jumps with meaningless labels like tc0pE and IlaiV, (2) every string literal including domain names, command names, and file paths encoded using hexadecimal or octal escape sequences, and (3) all variable and function names replaced with randomly generated strings. Once loaded via Composer autoloading, the payload connects to a command-and-control server at helper.leuleu.net on port 2096 using PHP's stream_socket_client() function over raw TCP. All traffic between the RAT and C2 is encrypted using AES-128-CTR with a hardcoded 16-byte key (esCAmxUoJkIjTV0n). The RAT transmits a full system profile including hostname, OS version, user permissions, and a machine unique ID, then enters a persistent command loop retrying the connection every 15 seconds if disconnected. The RAT probes disable_functions and selects the first available execution method from: popen, proc_open, exec, shell_exec, system, passthru. Supported C2 commands include: ping (heartbeat every 60 seconds), info (system reconnaissance), cmd (shell command execution), powershell (PowerShell command execution), run (background shell execution), screenshot (using imagegrabscreen()), download (arbitrary file reading), upload (file writing with rwx permissions), and stop (socket termination). The C2 domain helper.leuleu.net resolves to 173.230.142.118, hosted on Linode (Akamai Technologies) infrastructure in the United States. The parent domain leuleu.net is protected by Cloudflare DNS. At the time of public disclosure, the C2 server was non-responsive, though the RAT's persistent retry loop means compromised hosts will reconnect automatically if the server comes back online. Any Laravel application that installed these packages has a persistent RAT running within the same PHP process as the web application, with access to environment variables, database credentials, API keys, and secrets stored in .env files. The RAT is cross-platform, functioning on Windows, macOS, and Linux systems. The packages required ext-mongodb, ext-openssl, deerdama/console-zoo-laravel, and ircmaxell/random-lib as dependencies. The malicious packages were flagged by Aikido security scanner and remain documented on Packagist with malware warnings.
---
**Revalidated on 2026-03-12**
Eight days after initial public disclosure, the nhattuanbl supply chain attack remains an active and unresolved threat. Despite Socket.dev's takedown request submitted on March 3 and broad media coverage on March 4, the three weaponized packages (lara-helper, simple-queue, lara-swagger) remain listed on Packagist.org. The only mitigation is an Aikido security scanner flag displaying a prominent 'Versions of this package have been flagged as malware by Aikido' warning on each package's Packagist page -- but the packages have not been delisted or made uninstallable. No official Composer security advisory has been issued through Packagist's advisory database. The Jamaica CIRT elevated this to a national-level advisory (JMCIRT-SA-2026-007) with a Critical rating, recommending organizations treat any system that installed the affected packages as fully compromised, remove all traces, rotate all credentials, and rebuild from trusted sources. The SecuriTricks attack report confirmed the SHA-256 hash of the malicious payload (a493ce9509c5180e997a04cab2006a48202afbb8edfa15149a4521067191ead7) and provided comprehensive MITRE ATT&CK mapping across 8 techniques. The OffSeq threat intelligence radar, which last updated this threat entry on March 11, 2026, continues to classify it as an active campaign with no documented resolution. While the C2 server at helper.leuleu.net:2096 was non-responsive at the time of reporting, the RAT's persistent 15-second retry loop means any C2 reactivation would instantly re-establish attacker access. The affected regions span globally including the United States, Germany, United Kingdom, France, Canada, Australia, Netherlands, Japan, India, and Brazil. The Packagist ecosystem's slow response to removing confirmed malware packages -- over a week after public disclosure -- highlights a significant gap in the PHP supply chain security posture compared to npm and PyPI, which typically delist malicious packages within hours of verified reports.
MITRE ATT&CK techniques used in TL-2026-0190
collection
T1005 Data from Local System; T1113 Screen Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
discovery
T1033 System Owner/User Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter
command-and-control
T1095 Non-Application Layer Protocol; T1573 Encrypted Channel
initial-access
privilege-escalation
T1546 Event Triggered Execution
credential-access
impact
resource-development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Affected products and versions in Fake Laravel Packages on Packagist Deploy Cross-Platform RAT
- nhattuanbl (Packagist) — lara-helper
Vulnerable versions: 5.2; 5.2.1; 5.3; 5.4; 5.4.1; 5.4.2; 5.4.3; 5.4.4; 5.4.5; 5.4.6 - nhattuanbl (Packagist) — simple-queue
Vulnerable versions: all - nhattuanbl (Packagist) — lara-swagger
Vulnerable versions: 1.4; 2.0; dev-master
Remediation for Fake Laravel Packages on Packagist Deploy Cross-Platform RAT
Immediate actions
- Audit all Composer dependencies for nhattuanbl/lara-helper, nhattuanbl/simple-queue, and nhattuanbl/lara-swagger
- Remove any identified malicious packages immediately: composer remove nhattuanbl/lara-helper nhattuanbl/simple-queue nhattuanbl/lara-swagger
- Block outbound connections to helper.leuleu.net and 173.230.142.118 at firewall/proxy level
- Treat any host that installed affected packages as fully compromised
- Rotate all secrets accessible from the application environment including database passwords, API keys, and .env values
Workarounds
- Use composer audit to check for known malicious packages
- Review composer.lock for any references to nhattuanbl vendor packages
- Search for src/helper.php files containing obfuscated goto-based control flow
Longer-term hardening
- Implement Composer package integrity verification and lockfile auditing in CI/CD pipelines
- Deploy software composition analysis (SCA) tools to detect malicious dependencies
- Enforce package allowlisting for critical applications
- Monitor outbound TCP connections from PHP processes for anomalous C2 communication
- Implement network segmentation to limit lateral movement from compromised developer environments
Weaknesses (CWE) in Fake Laravel Packages on Packagist Deploy Cross-Platform RAT
Timeline of Fake Laravel Packages on Packagist Deploy Cross-Platform RAT
- Packagist account nhattuanbl registered, establishing long-term legitimacy for future supply chain attack
- Threat actor begins publishing packages to Packagist under nhattuanbl, including clean decoy packages (lara-media, snooze, syslog) to build credibility
- nhattuanbl/lara-swagger v2.0 published with hard dependency on lara-helper, creating transitive malware delivery chain
- nhattuanbl/lara-helper v5.5.1 published — latest version containing RAT payload in src/helper.php
- Last Packagist auto-sync for nhattuanbl packages recorded
- OffSeq Threat Radar adds campaign to live threat intelligence tracking database, categorized as active campaign with medium severity [Source: https://radar.offseq.com/threat/malicious-packagist-packages-disguised-as-laravel--5cae3aaa]
- SecuriTricks publishes attack report confirming SHA-256 hash a493ce9509c5180e997a04cab2006a48202afbb8edfa15149a4521067191ead7 and mapping attack to 8 MITRE ATT&CK techniques [Source: https://securitricks.com/attackreports/malicious-packagist-packages-disguised-as-laravel-utilities-deploy-encrypted-rat]
- Aikido security scanner flags nhattuanbl/lara-helper and nhattuanbl/lara-swagger with prominent ''flagged as malware'' warnings on their Packagist package pages [Source: https://packagist.org/packages/nhattuanbl/lara-helper]
- Jamaica Cyber Incident Response Team (CIRT) issues advisory JMCIRT-SA-2026-007 rating the threat as Critical, recommending immediate package removal, credential rotation, and network monitoring for C2 connections [Source: https://cirt.gov.jm/advisory/fake-laravel-packages-packagist-deploy-rat-windows-macos-and-linux]
- Aikido security scanner flags affected package versions as malware on Packagist
- The Hacker News, CybersecurityNews, GBHackers, SC Media, and others publish reports on the supply chain attack
- Socket.dev researcher Kush Pandya publishes analysis identifying malicious RAT payload in nhattuanbl packages
- C2 server at helper.leuleu.net:2096 confirmed non-responsive at time of public reporting, though RAT retry loop remains active
- OffSeq Threat Radar last modified entry confirms threat status remains Active with no official resolution or package removal documented as of this date [Source: https://radar.offseq.com/threat/malicious-packagist-packages-disguised-as-laravel--5cae3aaa]
- Revalidation confirms packages still listed on Packagist.org with Aikido malware flags but not removed; no Composer security advisory issued; C2 server remains non-responsive but RAT retry loop persists on any compromised hosts [Source: https://packagist.org/packages/nhattuanbl/lara-helper]
- As of 2026-05-29, the nhattuanbl Packagist/Laravel RAT campaign is dormant: its C2 (helper.leuleu.net:2096) was already non-responsive at Socket's Mar 3 disclosure and the malicious lara-helper/simple-queue are no longer on the actor's Packagist page. But it is not fully resolved, as lara-swagger reportedly stayed listed and installed hosts retain the persistent RAT until remediated.
Sources cited for Fake Laravel Packages on Packagist Deploy Cross-Platform RAT
- Socket.dev: Malicious Packagist Packages Disguised as Laravel Utilities
- The Hacker News: Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
- CybersecurityNews: Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT
- GBHackers: Malicious Laravel Packages Deploy PHP RAT
- SC Media: Malicious PHP packages deliver cross-platform RAT
- CyberPress: Malicious Laravel Packages Deploy PHP RAT
- Security Arsenal: Cross-Platform RAT via Malicious Laravel Packages
- Packagist: nhattuanbl/lara-helper
- Packagist: nhattuanbl/lara-swagger
- Socket.dev: lara-helper File Explorer
Detection coverage for TL-2026-0190
As of 2026-03-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0190 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.