PEAR PHP site breach lets hackers slip malware into official download
arstechnica.com
arstechnica.com
That said, this would really only apply to someone who rebuilt their Apache instance in the last six months, or manually re-installed PEAR. It has the potential to effect big cPanel based hosting companies like GoDaddy, but only if they were deploying new server instances and not using an image to do it (for some reason).
Main Point:
>If you installed PEAR on your Linux system using your distribution's package management tool, it is hugely unlikely that go-pear.phar was included with it... and even more unlikely that you would have used it on that system.