CuraSec

tag: Packagist · 1 items

2026-09-01 · The Hacker News · source ↗ #supply-chain#packagist#ios-spyware
  • Engineer — Plan: Packagist supply-chain compromise is relevant to any team running PHP/Composer-based web properties; audit your Composer dependency tree against the 13 named packages and enable automated SCA scanning in CI to catch future malicious packages.
  • SOC/IR — Learn: The attack chain — trojanized Packagist packages injecting JavaScript that fingerprints and exploits unpatched iOS visitors — is a useful TTP reference, but no IOCs or SIEM-ready indicators are provided, making immediate detection work impractical.
  • Leader — Skip