Grey.ooo
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
exakat@lemmy.world to PHP@lemmy.worldEnglish · 16 days ago

Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages

securityonline.info

external-link
message-square
6
link
fedilink
8
external-link

Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages

securityonline.info

exakat@lemmy.world to PHP@lemmy.worldEnglish · 16 days ago
message-square
6
link
fedilink
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
alert-triangle
You must log in or # to comment.
  • SavinDWhales@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    14 days ago

    That website is malicious. First thing after loading: allow notifications?

    Couldn’t get past the cookie banner, so…

  • exakat@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    14 days ago

    Another source for this info: https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos

  • LurkingLuddite@piefed.social
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    13
    ·
    16 days ago

    I mean if you’re using php in 2026…

    • greyscaleA
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      16 days ago

      🤡👞

      • LurkingLuddite@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        3
        ·
        15 days ago

        I didn’t specify why. Interesting how defensive you clowns get, though glad to see you didn’t forget your makeup.

        • greyscaleA
          link
          fedilink
          English
          arrow-up
          1
          ·
          15 days ago

          Half the internet runs on PHP bro. It pays a lot of rent and mortgages.

          The toolchain is less hellish than JS for sure.

          Its a pragmatic choice and its very easy to disregard you and opinions when its indistinguishable from 2005 skiddy talk.

PHP@lemmy.world

php@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !php@lemmy.world

<?

namespace lemmy\php;

/*

Welcome to the PHP community on Lemmy

#Rules:

1: Soon™

#Helpful stuff:

PHP Documentation

Composer

PHP Standards

#Common frameworks:

Symfony

Larvel

*/

echo “Welcome”;

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 14 users / day
  • 12 users / week
  • 53 users / month
  • 109 users / 6 months
  • 1 local subscriber
  • 417 subscribers
  • 123 Posts
  • 20 Comments
  • Modlog
  • mods:
  • Madpeter@lemmy.world
  • BE: 0.19.16
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org