2026-03-05 09:52:30
🧩 lara-swagger itself is clean but lists lara-helper as a #Composer dependency — silently pulling in the RAT during installation
🔒 The payload in helper.php uses heavy obfuscation: control flow manipulation, encoded domain names, randomized variable/function identifiers to bypass static analysis
🌐 Once loaded, the RAT connects to C2 server helper.leuleu[.]net:2096, sends system r…