Threat reportSupply ChainTL-2026-0217
Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)
Malicious Packagist Packages Deliver Cross-Platform PHP RAT (TL-2026-0217), also tracked as Fake Laravel RAT Campaign, is a high-severity supply-chain compromise, first published 2026-03-12. It has no confirmed attribution, affects nhattuanbl lara-helper, maps to 15 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 18 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-0217
- Threat ID
- TL-2026-0217
- Also known as
- Fake Laravel RAT Campaign, nhattuanbl Supply Chain Attack
- Severity
- HIGH
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, web-development, saas, e-commerce, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
How Malicious Packagist Packages Deliver Cross-Platform PHP RAT works
Six Packagist packages published by threat actor nhattuanbl masquerade as Laravel utilities while deploying a cross-platform PHP RAT with full C2 capabilities including shell execution, screenshot capture, file operations, and PowerShell access. The RAT connects to helper.leuleu.net:2096 via persistent TCP socket and activates at application boot through Laravel service provider auto-loading.
A sophisticated supply chain attack targeting the PHP/Composer ecosystem was discovered in March 2026, involving six packages published on Packagist by a threat actor operating under the handle nhattuanbl. The campaign employed a credibility-building strategy: three packages (lara-media, snooze, syslog) were completely clean and served to establish author legitimacy, while two packages (lara-helper and simple-queue) contained an identical malicious payload hidden in src/helper.php. A sixth package (lara-swagger) acted as a dependency-chain carrier, listing lara-helper as a hard Composer dependency so that installing it automatically pulled in the RAT.
The Packagist account was created in December 2015 but remained dormant until June 2024, when the threat actor began publishing packages over a six-month window ending in December 2024. The lara-helper package accumulated 37 installs, simple-queue had 29, and lara-swagger reached 49 downloads before discovery.
The malicious payload in src/helper.php is a fully-featured cross-platform remote access trojan (RAT) functional on Windows, macOS, and Linux. It employs multiple obfuscation techniques to complicate static analysis: control flow obfuscation, encoded domain names and command identifiers, and randomized variable and function naming. The RAT establishes a persistent TCP connection to the C2 server at helper.leuleu.net on port 2096 using PHP stream_socket_client(). If the connection drops, it automatically retries every 15 seconds indefinitely. The operator can redirect it to a new host without modifying the on-disk payload.
Before executing commands, the RAT probes the PHP environment for disabled_functions and selects the first available execution method from: popen, proc_open, exec, shell_exec, system, or passthru. The supported command set includes: ping (60-second heartbeat), info (system reconnaissance transmission), cmd (shell command execution), powershell (PowerShell command execution), run (background shell execution), screenshot (screen capture via imagegrabscreen()), download (file reading from disk), upload (file writing with universal read/write/execute permissions 0777), and stop (socket termination and exit).
Activation occurs at application boot via Laravel service provider registration or during class autoloads, meaning the RAT runs in the same PHP process as the web application with identical filesystem permissions and full access to environment variables including database credentials, API keys, and .env contents. This makes credential harvesting trivial without any additional exploitation.
The campaign was discovered and publicly disclosed on March 4, 2026 by Socket security researcher Kush Pandya. The packages were flagged as malware by Aikido security analysis on Packagist. At time of initial disclosure, the C2 server at helper.leuleu.net:2096 was not responding, though the RAT remains on disk and retries connections indefinitely. All versions of the three malicious packages are compromised with no safe iteration available.
MITRE ATT&CK techniques used in TL-2026-0217
collection
T1005 Data from Local System; T1113 Screen Capture
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
command-and-control
T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
initial-access
persistence
T1547 Boot or Logon Autostart Execution
resource-development
Affected products and versions in Malicious Packagist Packages Deliver Cross-Platform PHP RAT
- nhattuanbl — lara-helper
Vulnerable versions: all versions: 5.2, 5.2.1, 5.3, 5.4, 5.4.1, 5.4.2, 5.4.3, 5.4.4, 5.4.5, 5.4.6, 5.4.7, 5.4.8, 5.5, 5.5.1, dev-master - nhattuanbl — simple-queue
Vulnerable versions: all versions - nhattuanbl — lara-swagger
Vulnerable versions: 1.4, 2.0, dev-master
Remediation for Malicious Packagist Packages Deliver Cross-Platform PHP RAT
Immediate actions
- Audit all Composer dependencies for nhattuanbl packages: grep -r 'nhattuanbl/lara-helper\|nhattuanbl/simple-queue\|nhattuanbl/lara-swagger' --include='composer.*'
- Remove malicious packages: composer remove nhattuanbl/lara-helper nhattuanbl/simple-queue nhattuanbl/lara-swagger
- Delete vendor directory contents for affected packages and run composer install from clean lock file
- Block outbound connections to helper.leuleu.net and port 2096 at network perimeter
- Monitor network traffic for TCP connections to helper.leuleu.net:2096
- Rotate ALL credentials accessible from the application environment: database passwords, API keys, .env secrets
Workarounds
- If removal is not immediately possible, add helper.leuleu.net to hosts file pointing to 127.0.0.1
- Disable PHP functions used by the RAT in php.ini: popen, proc_open, exec, shell_exec, system, passthru
- Restrict imagegrabscreen() in PHP configuration if screenshot capability is a concern
Longer-term hardening
- Implement Composer dependency scanning in CI/CD pipelines using tools like Socket, Snyk, or Aikido
- Enforce composer.lock pinning and audit dependency changes in code review
- Deploy network segmentation between development and production environments
- Restrict outbound server connections to known-good destinations via egress filtering
- Monitor for PHP processes spawning shell commands or network connections to unusual ports
- Implement Software Composition Analysis (SCA) tooling for all package managers
Weaknesses (CWE) in Malicious Packagist Packages Deliver Cross-Platform PHP RAT
Timeline of Malicious Packagist Packages Deliver Cross-Platform PHP RAT
- nhattuanbl Packagist account created, remaining dormant for nearly a decade
- Threat actor begins publishing packages on Packagist, starting with clean credibility-building packages (lara-media, snooze, syslog)
- lara-swagger v2.0 published on Packagist with hard dependency on malicious lara-helper, acting as dependency-chain carrier
- lara-helper v5.5.1 published (latest malicious version), containing PHP RAT payload in src/helper.php
- Six-month package publishing window concludes with all six packages live on Packagist
- C2 server at helper.leuleu.net:2096 observed as non-responsive, though RAT on disk retries connection every 15 seconds indefinitely
- Packages flagged as malware by Aikido security analysis on Packagist
- The Hacker News, CybersecurityNews, GBHackers, SecurityArsenal, and SC Media publish coverage of the supply chain attack
- Socket security researcher Kush Pandya discovers and publicly discloses the malicious packages, triggering broad industry coverage
- Jamaica CIRT publishes formal advisory with IOCs and remediation guidance for affected organizations
- Socket publishes expanded analysis linking campaign to broader trojanized jQuery and FUNNULL redirect payload distribution
- As of 2026-05-29, the nhattuanbl Packagist RAT campaign is contained: packages were Aikido-flagged and taken down, the actor's publishing window closed Dec 2024 with no new packages, and the helper.leuleu.net:2096 C2 remains non-responsive. It is not active or spreading, but indefinitely-retrying on-disk RATs on unremediated hosts justify continued MONITORING (no CVE/KEV to patch).
Sources cited for Malicious Packagist Packages Deliver Cross-Platform PHP RAT
- Socket: 6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads
- Socket: Malicious Packagist Packages Disguised as Laravel Utilities
- The Hacker News: Fake Laravel Packages on Packagist Deploy RAT
- CybersecurityNews: Malicious Packages Disguised as Laravel Utilities
- SecurityArsenal: Cross-Platform RAT via Malicious Laravel Packages
- CyberPress: Malicious Laravel Packages Deploy PHP RAT
- GBHackers: Malicious Laravel Packages Deploy PHP RAT
- Jamaica CIRT Advisory: Fake Laravel Packages Deploy RAT
- SecuriTricks: Malicious Packagist Packages Deploy Encrypted RAT
- SC Media: Malicious PHP packages deliver cross-platform RAT
- Packagist: nhattuanbl/lara-helper
- Packagist: nhattuanbl/lara-swagger
Detection coverage for TL-2026-0217
As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0217 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.