Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
ID: 705ce09d-a573-57b7-90b1-88f0c2e12ade
STIX ID: report--705ce09d-a573-57b7-90b1-88f0c2e12ade
Feed Name: Aikido Security's Blog
A supply-chain attack was discovered on May 22, 2026 targeting laravel-lang repositories: attackers published 233 malicious version tags that point to commits in a malicious fork, adding a PHP dropper (src/helpers.php) which fetches a large credential-stealing payload from flipboxstudio.info that exfiltrates cloud, infrastructure, developer, browser, password-manager and cryptocurrency wallet secrets; Packagist removed the malicious versions and the report provides IOCs and remediation/detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
