{
  "title": "Packagist GitHub Postinstall Hook Malware Campaign",
  "summary": "A campaign inserted malicious package.json postinstall hooks into Packagist-linked GitHub repositories, causing npm install workflows to download and execute a GitHub Releases binary as /tmp/.sshd.",
  "date": "2026-05-24",
  "severity": "high",
  "tags": [
    "supply-chain",
    "packagist",
    "github",
    "npm",
    "postinstall"
  ],
  "sources_count": 5,
  "indicators": {
    "slug": "packagist-github-postinstall-hook-campaign",
    "since": "2026-05-24T00:00:00Z",
    "until": "unknown",
    "ecosystem": "",
    "cves": [],
    "cwes": [],
    "advisoryIds": [],
    "products": [],
    "packages": [],
    "versions": [],
    "affectedVersions": [],
    "fixedVersions": [],
    "files": [],
    "paths": [],
    "services": [],
    "domains": [
      "github.com"
    ],
    "urls": [
      "https://github.com/parikhpreyash4/systemd-network-helper-aa5c751f/releases/latest/download/gvfsd-network"
    ],
    "ips": [],
    "hashes": [],
    "processPatterns": [],
    "networkPatterns": [],
    "telemetrySelectors": []
  }
}