logo

Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos

ID: 35d7f10a-69d6-5f2a-aad2-a27524ee8dd8

STIX ID: report--35d7f10a-69d6-5f2a-aad2-a27524ee8dd8

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Guru Baran

...
...

A sophisticated supply-chain attack discovered in May 2026 compromised the Laravel-Lang ecosystem by manipulating Git tags to distribute Composer-autoloaded PHP backdoors across 233 package versions in ~700 GitHub repositories; the dropper fingerprints hosts, disables SSL verification, fetches a secondary PHP credential stealer with 15 collection modules, encrypts harvested secrets with AES‑256 and exfiltrates them to flipboxstudio.info before cleaning traces. The report provides OS-specific execution details, IOCs (domains, URLs, file paths, an artifact and metadata), and recommends rotating exposed credentials, auditing composer.lock files, monitoring outbound traffic, and rebuilding affected systems from known-good images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.