Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
Blog post from Socket
Researchers at Socket identified a coordinated supply chain attack targeting eight Composer packages on Packagist, which included a malicious postinstall script in their package.json files. This script attempted to download and execute a binary from a GitHub Releases URL, exploiting the fact that these packages shipped JavaScript build tooling alongside PHP code. The attack highlighted a vulnerability where developers might overlook package.json scripts while focusing on Composer metadata. The malicious script was detected across eight different package versions, downloading an unauthenticated binary and executing it in the background with weakened security measures. The attack appeared to be part of a broader campaign, as further GitHub searches revealed numerous instances of similar scripts across various Node.js repositories. Researchers found that the malicious scripts were introduced through commits to upstream GitHub repositories, which were then reflected in Packagist's branch-tracking package versions. This incident underscores the importance for developers to inspect package.json files within Packagist packages that include JavaScript build tooling, as these scripts can provide a pathway for remote code execution during installation or build processes. Socket flagged the affected packages and reported them to Packagist, which removed them to mitigate the risk.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.