# Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)

> Six Packagist packages published by threat actor nhattuanbl masquerade as Laravel utilities while deploying a cross-platform PHP RAT with full C2 capabilities including shell execution, screenshot capture, file operations, and PowerShell access. The RAT connects to helper.leuleu.net:2096 via persistent TCP socket and activates at application boot through Laravel service provider auto-loading.

- **Published:** 2026-03-12T12:00:00Z
- **Last reviewed:** 2026-03-12T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0217
- **ID:** TL-2026-0217
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A sophisticated supply chain attack targeting the PHP/Composer ecosystem was discovered in March 2026, involving six packages published on Packagist by a threat actor operating under the handle nhattuanbl. The campaign employed a credibility-building strategy: three packages (lara-media, snooze, syslog) were completely clean and served to establish author legitimacy, while two packages (lara-helper and simple-queue) contained an identical malicious payload hidden in src/helper.php. A sixth package (lara-swagger) acted as a dependency-chain carrier, listing lara-helper as a hard Composer dependency so that installing it automatically pulled in the RAT.

The Packagist account was created in December 2015 but remained dormant until June 2024, when the threat actor began publishing packages over a six-month window ending in December 2024. The lara-helper package accumulated 37 installs, simple-queue had 29, and lara-swagger reached 49 downloads before discovery.

The malicious payload in src/helper.php is a fully-featured cross-platform remote access trojan (RAT) functional on Windows, macOS, and Linux. It employs multiple obfuscation techniques to complicate static analysis: control flow obfuscation, encoded domain names and command identifiers, and randomized variable and function naming. The RAT establishes a persistent TCP connection to the C2 server at helper.leuleu.net on port 2096 using PHP stream_socket_client(). If the connection drops, it automatically retries every 15 seconds indefinitely. The operator can redirect it to a new host without modifying the on-disk payload.

Before executing commands, the RAT probes the PHP environment for disabled_functions and selects the first available execution method from: popen, proc_open, exec, shell_exec, system, or passthru. The supported command set includes: ping (60-second heartbeat), info (system reconnaissance transmission), cmd (shell command execution), powershell (PowerShell command execution), run (background shell execution), screenshot (screen capture via imagegrabscreen()), download (file reading from disk), upload (file writing with universal read/write/execute permissions 0777), and stop (socket termination and exit).

Activation occurs at application boot via Laravel service provider registration or during class autoloads, meaning the RAT runs in the same PHP process as the web application with identical filesystem permissions and full access to environment variables including database credentials, API keys, and .env contents. This makes credential harvesting trivial without any additional exploitation.

The campaign was discovered and publicly disclosed on March 4, 2026 by Socket security researcher Kush Pandya. The packages were flagged as malware by Aikido security analysis on Packagist. At time of initial disclosure, the C2 server at helper.leuleu.net:2096 was not responding, though the RAT remains on disk and retries connections indefinitely. All versions of the three malicious packages are compromised with no safe iteration available.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1571 Non-Standard Port
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [Socket: 6 Malicious Packagist Themes Ship Trojanized jQuery and FUNNULL Redirect Payloads](https://socket.dev/blog/6-malicious-packagist-themes-ship-trojanized-jquery)
- [Socket: Malicious Packagist Packages Disguised as Laravel Utilities](https://socket.dev/blog/malicious-packagist-packages-disguised-as-laravel-utilities)
- [The Hacker News: Fake Laravel Packages on Packagist Deploy RAT](https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html)
- [CybersecurityNews: Malicious Packages Disguised as Laravel Utilities](https://cybersecuritynews.com/malicious-packages-disguised-as-laravel-utilities/)
- [SecurityArsenal: Cross-Platform RAT via Malicious Laravel Packages](https://securityarsenal.com/blog/cross-platform-rat-delivered-via-malicious-laravel-packages-on-packagist)
- [CyberPress: Malicious Laravel Packages Deploy PHP RAT](https://cyberpress.org/malicious-laravel-packages-deploy-rat/)
- [GBHackers: Malicious Laravel Packages Deploy PHP RAT](https://gbhackers.com/malicious-laravel-packages/)
- [Jamaica CIRT Advisory: Fake Laravel Packages Deploy RAT](https://cirt.gov.jm/advisory/fake-laravel-packages-packagist-deploy-rat-windows-macos-and-linux)
- [SecuriTricks: Malicious Packagist Packages Deploy Encrypted RAT](https://securitricks.com/attackreports/malicious-packagist-packages-disguised-as-laravel-utilities-deploy-encrypted-rat)
- [SC Media: Malicious PHP packages deliver cross-platform RAT](https://www.scworld.com/brief/malicious-php-packages-deliver-cross-platform-rat-to-laravel-applications)
- [Packagist: nhattuanbl/lara-helper](https://packagist.org/packages/nhattuanbl/lara-helper)
- [Packagist: nhattuanbl/lara-swagger](https://packagist.org/packages/nhattuanbl/lara-swagger)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0217
