Thirteen malicious Composer packages allegedly bent trusted web pages into a delivery path for ad fraud, redirects, and a spyware campaign aimed at unpatched iOS devices.
A reported package-chain abuse on Composer's ecosystem shows how a single injected script can turn ordinary mobile page views into a credential-harvesting event.
A Packagist supply-chain abuse case shows how a single trojanized Composer theme can turn a normal website into a browser-delivered payload platform for redirects, fraud, spyware, and possible wallet theft.
A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.
Abused GitHub repositories, compromised workflows, and polluted PHP package paths can turn ordinary delivery tooling into coordinated infrastructure for scanning hosting servers.
A campaign tied to PolinRider has put malicious packages and browser extensions into npm, Packagist, Go, and Google Chrome, showing how one delivery pattern can travel across very different trust systems.
A maintainer-account takeover can do more damage than a single malicious file, especially when one publish pipeline reaches several software ecosystems at once.
A legitimate Laravel package surfaced with hidden obfuscated JavaScript, showing how development refs and package trust can become a developer-side attack surface.
A compromise in several Laravel-Lang PHP packages shows how a low-profile update path can become a high-trust delivery channel for credential theft.
A warning tied to PHP dependency pipelines shows how a workflow-format edge case can turn routine CI activity into a credential-exposure problem.