Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,356
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers at Socket identified a coordinated supply chain attack targeting eight Composer packages on Packagist, which included a malicious postinstall script in their package.json files. This script attempted to download and execute a binary from a GitHub Releases URL, exploiting the fact that these packages shipped JavaScript build tooling alongside PHP code. The attack highlighted a vulnerability where developers might overlook package.json scripts while focusing on Composer metadata. The malicious script was detected across eight different package versions, downloading an unauthenticated binary and executing it in the background with weakened security measures. The attack appeared to be part of a broader campaign, as further GitHub searches revealed numerous instances of similar scripts across various Node.js repositories. Researchers found that the malicious scripts were introduced through commits to upstream GitHub repositories, which were then reflected in Packagist's branch-tracking package versions. This incident underscores the importance for developers to inspect package.json files within Packagist packages that include JavaScript build tooling, as these scripts can provide a pathway for remote code execution during installation or build processes. Socket flagged the affected packages and reported them to Packagist, which removed them to mitigate the risk.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.