How do users report a composer package that is distributing a Remote Access Trojan (RAT) on packagist for removal/warning?
eg.
https://intel.aikido.dev/packages/packagist/nhattuanbl/lara-helper
https://packagist.org/packages/nhattuanbl/lara-helper
Payload: https://gitlab.com/nhattuanbl/lara-helper/-/blob/master/src/helper.php