CRITICALAdvisorySep 01, 2026
Action required
Identify and quarantine any use of malicious Packagist packages in your supply chain. Cross-reference developer environments and production deployments against the IOC list. Scan logs for Composer installations from Packagist between March 2026 and present. Brief finance and crypto-custodian teams on wallet seed exposure risk.
Affected products
ComposerOphimCMSiOSFunnull
Linked articles