Breach404
Back to Insights
Cybersecurity2 min readMay 23, 2026

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

Attackers compromised eight PHP packages on Packagist by injecting malware hosted on GitHub, exploiting the supply chain to potentially infect applications that depend on these libraries. You should immediately audit your dependencies on Packagist for any

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free