The PHP PEAR go-pear.phar Backdoor
Updated 5 Oct 2026 · Incident date 20 Dec 2018 · install script
go-pear.phar (PEAR installer) - official copy replaced on pear.php.netgo-pear.pharThe official go-pear.phar installer on pear.php.net was replaced with a tampered copy after the 20 December 2018 release. The copy started a Perl reverse shell to 104.131.154.154. The PEAR team found the problem on 19 January 2019.
The same file on GitHub was not affected.
What happened
Attackers gained the ability to change files on the pear.php.net server. Rapid7 reports that the PEAR team announced the breach on 19 January 2019 and that the exposure window could reach back six months. The PEAR administrators said that anyone who downloaded go-pear.phar in the past six months must get a new copy.
The Hacker News reports that the malicious file was planted after the 20 December 2018 release. It says the code spawned a Perl reverse shell to 104.131.154.154, which gave the attacker control of the server. The code needs a shell and Perl on the system.
The Hacker News reports no evidence of an earlier compromise before 20 December 2018. The clean file on GitHub was in the pear/pearweb_phars repository. The PEAR team released version 1.10.10 on GitHub with GPG signatures.
Unix, Linux and BSD systems that installed PEAR automatically had the greatest exposure. Windows and Mac users were affected only if they installed it by hand in the window.
Affected versions
The affected item is the copy of go-pear.phar served from pear.php.net during the window. It is not a numbered release.
- Exposure: after 20 December 2018 until the site went offline in mid-January 2019
- Clean source: GitHub
pear/pearweb_phars - Clean release named by The Hacker News: 1.10.10
Indicators of compromise
- MD5 of the tampered
go-pear.phar:1e26d9dd3110af79a9595f1a77a82de7(Rapid7) - Reverse shell address:
104.131.154.154 - A Perl process with a network connection to that address
The Hacker News also links the address to the domain bestlinuxgames.com, which it believes was a compromised host. I could not confirm that link in another source.
How to check
Hash any go-pear.phar file you downloaded and compare it with the MD5 above.
find / -name go-pear.phar -exec md5sum {} + 2>/dev/nullOn macOS use md5 -r instead of md5sum. Then check for connections to the address.
grep -r "104.131.154.154" /var/log 2>/dev/null
What to do now
- If the hash matches, treat the server as compromised and investigate it.
- Download a clean
go-pear.pharfrom GitHub and check the hash and GPG signature. - Run integrity checks on PHP-enabled services and watch for unusual behavior.
- Block the reverse shell address at your firewall.
- Keep PHP at a current, patched version.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here the installer gained execution and outbound networking. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 11 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED pear.php It now downloads from the internet. It did not before.
Frequently asked questions
What happened to go-pear.phar?
A tampered copy on pear.php.net, planted after 20 December 2018, spawned a Perl reverse shell to 104.131.154.154. The PEAR team announced the breach on 19 January 2019.
How do I check if my go-pear.phar is malicious?
Compute its MD5 hash and compare it with the tampered file hash 1e26d9dd3110af79a9595f1a77a82de7. If it matches, treat the server as compromised.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- arrayref / internment / append-only-vec crates.io compromise 20 Aug 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- SleeperGem dormant-maintainer RubyGems hijacks 18 Jul 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.