PEAR stands for PHP Extension and Application Repository. Using PEAR, you can download and manage various PHP libraries that allow you to easily implement various functionalities like login authentication, networking, and so on without needing to write the code from scratch.
Someone has hacked the PHP PEAR website (pear.php.net) and replaced the original PEAR installation package with a malicious package.
If you have downloaded the PEAR package manager—which is go-pear.phar file—from the official website in the past six months, kindly consider you are affected.
As soon as possible, you should download and install the latest version from the GitHub repository: https://github.com/pear/pearweb_phars, which is secure.
Currently, the PEAR website is down. And the PEAR team is doing a forensic investigation to find more details about the hack.
Affected Version: v1.10.9
Latest Version: v1.10.10
You may check the official twitter handle for the latest updates.