Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages

https://securityonline.info/php-composer-packages-malicious-js-postinstall-backdoor/

8 points · 6 comments · view on lemmy.world

6 Comments

SavinDWhales@lemmy.world · 3 pts · 76d

That website is malicious. First thing after loading: allow notifications?

Couldn't get past the cookie banner, so...

exakat@lemmy.world · 1 pts · 76d
LurkingLuddite@piefed.social · -11 pts · 78d (3 replies)

I mean if you're using php in 2026...

greyscale@lemmy.grey.ooo · 3 pts · 78d (2 replies)

🤡👞

LurkingLuddite@piefed.social · -2 pts · 77d (1 reply)

I didn't specify why. Interesting how defensive you clowns get, though glad to see you didn't forget your makeup.

greyscale@lemmy.grey.ooo · 1 pts · 77d

Half the internet runs on PHP bro. It pays a lot of rent and mortgages.

The toolchain is less hellish than JS for sure.

Its a pragmatic choice and its very easy to disregard you and opinions when its indistinguishable from 2005 skiddy talk.