# Fake Laravel Packages on Packagist Deploy Cross-Platform RAT via Supply Chain Compromise

> Threat actor nhattuanbl published six PHP packages to Packagist impersonating Laravel utilities, with three packages (lara-helper, simple-queue, lara-swagger) embedding or transitively pulling in an obfuscated Remote Access Trojan. The RAT connects to a C2 server at helper.leuleu.net:2096 using AES-128-CTR encrypted TCP, granting attackers full remote shell access, file read/write, screenshot capture, and credential theft from compromised Laravel application environments.

- **Published:** 2026-03-07T12:00:00Z
- **Last reviewed:** 2026-03-07T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0190
- **ID:** TL-2026-0190
- **Severity:** HIGH (CVSS 8.8)
- **Category:** SUPPLY_CHAIN
- **Status:** DORMANT
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A supply chain attack targeting the PHP developer ecosystem was discovered by Socket.dev researcher Kush Pandya in March 2026. The threat actor operating under the Packagist username 'nhattuanbl' (email: nhattuanbl.woop@gmail.com, account registered December 2015) published six packages between June and December 2024 that masqueraded as legitimate Laravel utility libraries. Three of the six packages served as clean credibility builders: nhattuanbl/lara-media, nhattuanbl/snooze, and nhattuanbl/syslog. Two packages — nhattuanbl/lara-helper (37 installs) and nhattuanbl/simple-queue (29 installs) — contained an identical malicious payload embedded in src/helper.php. A sixth package, nhattuanbl/lara-swagger (49 installs), contained no direct malicious code but declared nhattuanbl/lara-helper as a hard Composer dependency, ensuring the RAT was installed transitively whenever developers required the swagger utility. The malicious file src/helper.php is 27,340 bytes delivered as a single continuous line after the opening <?php tag. It employs three distinct obfuscation layers: (1) control flow shattered into hundreds of randomized goto jumps with meaningless labels like tc0pE and IlaiV, (2) every string literal including domain names, command names, and file paths encoded using hexadecimal or octal escape sequences, and (3) all variable and function names replaced with randomly generated strings. Once loaded via Composer autoloading, the payload connects to a command-and-control server at helper.leuleu.net on port 2096 using PHP's stream_socket_client() function over raw TCP. All traffic between the RAT and C2 is encrypted using AES-128-CTR with a hardcoded 16-byte key (esCAmxUoJkIjTV0n). The RAT transmits a full system profile including hostname, OS version, user permissions, and a machine unique ID, then enters a persistent command loop retrying the connection every 15 seconds if disconnected. The RAT probes disable_functions and selects the first available execution method from: popen, proc_open, exec, shell_exec, system, passthru. Supported C2 commands include: ping (heartbeat every 60 seconds), info (system reconnaissance), cmd (shell command execution), powershell (PowerShell command execution), run (background shell execution), screenshot (using imagegrabscreen()), download (arbitrary file reading), upload (file writing with rwx permissions), and stop (socket termination). The C2 domain helper.leuleu.net resolves to 173.230.142.118, hosted on Linode (Akamai Technologies) infrastructure in the United States. The parent domain leuleu.net is protected by Cloudflare DNS. At the time of public disclosure, the C2 server was non-responsive, though the RAT's persistent retry loop means compromised hosts will reconnect automatically if the server comes back online. Any Laravel application that installed these packages has a persistent RAT running within the same PHP process as the web application, with access to environment variables, database credentials, API keys, and secrets stored in .env files. The RAT is cross-platform, functioning on Windows, macOS, and Linux systems. The packages required ext-mongodb, ext-openssl, deerdama/console-zoo-laravel, and ircmaxell/random-lib as dependencies. The malicious packages were flagged by Aikido security scanner and remain documented on Packagist with malware warnings.

---

**Revalidated on 2026-03-12**

Eight days after initial public disclosure, the nhattuanbl supply chain attack remains an active and unresolved threat. Despite Socket.dev's takedown request submitted on March 3 and broad media coverage on March 4, the three weaponized packages (lara-helper, simple-queue, lara-swagger) remain listed on Packagist.org. The only mitigation is an Aikido security scanner flag displaying a prominent 'Versions of this package have been flagged as malware by Aikido' warning on each package's Packagist page -- but the packages have not been delisted or made uninstallable. No official Composer security advisory has been issued through Packagist's advisory database. The Jamaica CIRT elevated this to a national-level advisory (JMCIRT-SA-2026-007) with a Critical rating, recommending organizations treat any system that installed the affected packages as fully compromised, remove all traces, rotate all credentials, and rebuild from trusted sources. The SecuriTricks attack report confirmed the SHA-256 hash of the malicious payload (a493ce9509c5180e997a04cab2006a48202afbb8edfa15149a4521067191ead7) and provided comprehensive MITRE ATT&CK mapping across 8 techniques. The OffSeq threat intelligence radar, which last updated this threat entry on March 11, 2026, continues to classify it as an active campaign with no documented resolution. While the C2 server at helper.leuleu.net:2096 was non-responsive at the time of reporting, the RAT's persistent 15-second retry loop means any C2 reactivation would instantly re-establish attacker access. The affected regions span globally including the United States, Germany, United Kingdom, France, Canada, Australia, Netherlands, Japan, India, and Brazil. The Packagist ecosystem's slow response to removing confirmed malware packages -- over a week after public disclosure -- highlights a significant gap in the PHP supply chain security posture compared to npm and PyPI, which typically delist malicious packages within hours of verified reports.

## MITRE ATT&CK

- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1546 Event Triggered Execution
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1069 Permission Groups Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1095 Non-Application Layer Protocol
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1565 Data Manipulation

## Sources

- [Socket.dev: Malicious Packagist Packages Disguised as Laravel Utilities](https://socket.dev/blog/malicious-packagist-packages-disguised-as-laravel-utilities)
- [The Hacker News: Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux](https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html)
- [CybersecurityNews: Malicious Packages Disguised as Laravel Utilities Deploy PHP RAT](https://cybersecuritynews.com/malicious-packages-disguised-as-laravel-utilities/)
- [GBHackers: Malicious Laravel Packages Deploy PHP RAT](https://gbhackers.com/malicious-laravel-packages/)
- [SC Media: Malicious PHP packages deliver cross-platform RAT](https://www.scworld.com/brief/malicious-php-packages-deliver-cross-platform-rat-to-laravel-applications)
- [CyberPress: Malicious Laravel Packages Deploy PHP RAT](https://cyberpress.org/malicious-laravel-packages-deploy-rat/)
- [Security Arsenal: Cross-Platform RAT via Malicious Laravel Packages](https://securityarsenal.com/blog/cross-platform-rat-delivered-via-malicious-laravel-packages-on-packagist)
- [Packagist: nhattuanbl/lara-helper](https://packagist.org/packages/nhattuanbl/lara-helper)
- [Packagist: nhattuanbl/lara-swagger](https://packagist.org/packages/nhattuanbl/lara-swagger)
- [Socket.dev: lara-helper File Explorer](https://socket.dev/composer/package/nhattuanbl/lara-helper/files?version=5.4.7)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0190
