Packagist Supply Chain Attack Eight Composer Packages | MSSP Advisory
HighCredible Report
DateMay 23, 2026
📋Executive Summary
Eight Composer packages on Packagist were compromised with malicious code that downloads and executes a Linux binary from GitHub Releases. The attack bypassed composer.json files and instead inserted malicious code into package.json files, targeting JavaScript projects that use both PHP and JavaScript dependencies.
⚠️Why It Matters for MSSPs
Your development teams and clients building web applications likely pull from Packagist daily, and this attack specifically targets mixed PHP/JavaScript environments that most modern web projects use. If your RMM or PSA systems run any custom integrations built with Composer packages, you could unknowingly execute malware on systems that have direct access to client networks.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.