Product
Packagist
- First Reported
- Jul 22, 2026
- Latest Reported
- Sep 17, 2026
Reported Context (3)
- Socket researchers identified malicious code in the dev-main version of visanduma/nova-two-factor, a Packagist package with more than 700,000 cumulative downloads, as the PolinRider campaign continues to spread through PolinRider Campaign Spreads Through Compromised GitHub Accounts and Packagist
- Socket’s Threat Research Team found 13 malicious Composer theme packages on Packagist, published across five vendor namespaces, that inject JavaScript into every page of the Vietnamese movie and comic streaming sites 13 Malicious Packagist Themes Deliver iOS Spyware and Steal Crypto Wallet Seeds
- Malicious Packagist development versions exposed a broader GitHub Actions campaign that abuses compromised repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability, and harvest Compromised GitHub Actions Repositories Fuel cPanel/WHM Exploitation and Credential Theft
CVE (4)
People (2)
MITRE ATT&CK (28)
Vendors (4)
Products (22)
Tools (8)
Industries (3)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.