Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A supply chain attack has infected eight PHP packages on Packagist, executing a Linux binary downloaded from a GitHub repository via package.json postinstall scripts. This supply chain attack highlights the risks associated with cross-ecosystem attacks targeting multiple package managers and build tools, emphasizing the need for comprehensive security measures that go beyond traditio….

https://meta-news.info/ve…