Post #3110577
2026-06-03 01:30 UTC
The packages published by the user "spruko" are all executing arbitrary, obfuscated or malicious code… via "autoload.files" entry in composer.json
It reads an embedded payload from a fake `index.jpg` file, decodes it through multiple de-obfuscation functions, and executes it via `eval()` in almost ever php file.
I have no interest to investigate further, but somebody should look into it and take action.
https://packagist.org/users/spruko
https://github.com/spruko
Replies (0)
No replies.