logo

Threat Actor Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos

ID: cdf0c628-fa13-5460-82d5-5d22dc78c828

STIX ID: report--cdf0c628-fa13-5460-82d5-5d22dc78c828

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Lucas Martin

...
...

A supply-chain campaign compromised over 700 historical Git tags across Laravel-Lang repositories by pointing tags to malicious forks, causing an autoloaded PHP helper to execute a dropper that fetches a second-stage 5,900-line PHP infostealer. The stealer collects cloud credentials, SSH keys, CI/CD tokens, browser vaults, and other secrets, encrypts them with AES-256, and exfiltrates to flipboxstudio.info; Packagist has unlisted affected packages and immediate credential rotation and host rebuilds are advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.