Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos
ID: 35d7f10a-69d6-5f2a-aad2-a27524ee8dd8
STIX ID: report--35d7f10a-69d6-5f2a-aad2-a27524ee8dd8
Feed Name: cybersecurityNews.com
A sophisticated supply-chain attack discovered in May 2026 compromised the Laravel-Lang ecosystem by manipulating Git tags to distribute Composer-autoloaded PHP backdoors across 233 package versions in ~700 GitHub repositories; the dropper fingerprints hosts, disables SSL verification, fetches a secondary PHP credential stealer with 15 collection modules, encrypts harvested secrets with AES‑256 and exfiltrates them to flipboxstudio.info before cleaning traces. The report provides OS-specific execution details, IOCs (domains, URLs, file paths, an artifact and metadata), and recommends rotating exposed credentials, auditing composer.lock files, monitoring outbound traffic, and rebuilding affected systems from known-good images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
