News
2026-05-23
A coordinated supply‑chain attack compromised eight Composer packages on Packagist, injecting malware via package.json that downloads and executes a Linux binary from GitHub Releases.
cybersecurity
supply-chain
packagist
malware
github