The PHP PEAR go-pear.phar Backdoor

Updated 5 Oct 2026 · Incident date 20 Dec 2018 · install script

Packagego-pear.phar (PEAR installer) - official copy replaced on pear.php.net
Filego-pear.phar

The official go-pear.phar installer on pear.php.net was replaced with a tampered copy after the 20 December 2018 release. The copy started a Perl reverse shell to 104.131.154.154. The PEAR team found the problem on 19 January 2019.

The same file on GitHub was not affected.

What happened

Attackers gained the ability to change files on the pear.php.net server. Rapid7 reports that the PEAR team announced the breach on 19 January 2019 and that the exposure window could reach back six months. The PEAR administrators said that anyone who downloaded go-pear.phar in the past six months must get a new copy.

The Hacker News reports that the malicious file was planted after the 20 December 2018 release. It says the code spawned a Perl reverse shell to 104.131.154.154, which gave the attacker control of the server. The code needs a shell and Perl on the system.

The Hacker News reports no evidence of an earlier compromise before 20 December 2018. The clean file on GitHub was in the pear/pearweb_phars repository. The PEAR team released version 1.10.10 on GitHub with GPG signatures.

Unix, Linux and BSD systems that installed PEAR automatically had the greatest exposure. Windows and Mac users were affected only if they installed it by hand in the window.

Affected versions

The affected item is the copy of go-pear.phar served from pear.php.net during the window. It is not a numbered release.

Indicators of compromise

The Hacker News also links the address to the domain bestlinuxgames.com, which it believes was a compromised host. I could not confirm that link in another source.

How to check

Hash any go-pear.phar file you downloaded and compare it with the MD5 above.

find / -name go-pear.phar -exec md5sum {} + 2>/dev/null

On macOS use md5 -r instead of md5sum. Then check for connections to the address.

grep -r "104.131.154.154" /var/log 2>/dev/null

What to do now

  1. If the hash matches, treat the server as compromised and investigate it.
  2. Download a clean go-pear.phar from GitHub and check the hash and GPG signature.
  3. Run integrity checks on PHP-enabled services and watch for unusual behavior.
  4. Block the reverse shell address at your firewall.
  5. Keep PHP at a current, patched version.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here the installer gained execution and outbound networking. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old go-pear.phar-prev --new go-pear.phar-current
files scanned: 11

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    pear.php
           It now downloads from the internet. It did not before.

Frequently asked questions

What happened to go-pear.phar?

A tampered copy on pear.php.net, planted after 20 December 2018, spawned a Perl reverse shell to 104.131.154.154. The PEAR team announced the breach on 19 January 2019.

How do I check if my go-pear.phar is malicious?

Compute its MD5 hash and compare it with the tampered file hash 1e26d9dd3110af79a9595f1a77a82de7. If it matches, treat the server as compromised.

Sources

  1. rapid7.com/blog/post/2019/01/22/php-extension-and-application-repository-pear-compromise-what-you-need-to-know/
  2. thehackernews.com/2019/01/php-pear-hacked.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free