Packagist is the main package repository for PHP that was used to distribute malicious development versions of 10 packages associated with a compromised developer. The packages contained malicious GitHub Actions workflows that launched credential theft campaigns.