Friday 11 September 2026 13:25:04 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#Packagist


When a Theme Package Turns into a Trap for iPhones and Wallet Owners

Published: 02 September 2026 20:59Category: Malware & BotnetsAuthor: SIGNALMONK

Thirteen malicious Composer packages allegedly bent trusted web pages into a delivery path for ad fraud, redirects, and a spyware campaign aimed at unpatched iOS devices.

When a Dependency Becomes the Trapdoor: Packagist Themes and the iPhone Browser Risk

Published: 01 September 2026 12:22Category: Malware & BotnetsGeo: Europe / GermanyAuthor: SIGNALMONK

A reported package-chain abuse on Composer's ecosystem shows how a single injected script can turn ordinary mobile page views into a credential-harvesting event.

Malicious Theme Packages Turned Streaming Sites Into a Mobile Trap

Published: 01 September 2026 10:36Category: CybercrimeGeo: Asia / VietnamAuthor: CRYSTALPROXY

A Packagist supply-chain abuse case shows how a single trojanized Composer theme can turn a normal website into a browser-delivered payload platform for redirects, fraud, spyware, and possible wallet theft.

How a Trusted Build Pipeline Became a Launchpad for Server Attacks

Published: 23 July 2026 16:54Category: CybercrimeGeo: North America / USAAuthor: CRYSTALPROXY

A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.

When Trusted Automation Starts Hunting Hosts

Published: 23 July 2026 14:18Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

Abused GitHub repositories, compromised workflows, and polluted PHP package paths can turn ordinary delivery tooling into coordinated infrastructure for scanning hosting servers.

108 Poisoned Builds, One Shared Trap: The New Cross-Ecosystem Supply-Chain Wave

Published: 04 July 2026 14:07Category: Malware & BotnetsGeo: Asia / North KoreaAuthor: IRONQUERY

A campaign tied to PolinRider has put malicious packages and browser extensions into npm, Packagist, Go, and Google Chrome, showing how one delivery pattern can travel across very different trust systems.

Trusted Release Keys Turned Into a Supply-Chain Weapon

Published: 03 July 2026 08:16Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

A maintainer-account takeover can do more damage than a single malicious file, especially when one publish pipeline reaches several software ecosystems at once.

When a Dev Branch Turns Toxic: The Quiet Supply-Chain Trap Inside a PHP Package

Published: 02 June 2026 10:25Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A legitimate Laravel package surfaced with hidden obfuscated JavaScript, showing how development refs and package trust can become a developer-side attack surface.

A Quiet Dependency Turned Into a Credential Trap

Published: 23 May 2026 14:16Category: Malware & BotnetsAuthor: IRONQUERY

A compromise in several Laravel-Lang PHP packages shows how a low-profile update path can become a high-trust delivery channel for credential theft.

GitHub Actions Change Raises a Quiet but Serious Risk for Composer Workflows

Published: 14 May 2026 10:18Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A warning tied to PHP dependency pipelines shows how a workflow-format edge case can turn routine CI activity into a credential-exposure problem.