logo

Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer

ID: 705ce09d-a573-57b7-90b1-88f0c2e12ade

STIX ID: report--705ce09d-a573-57b7-90b1-88f0c2e12ade

Feed Name: Aikido Security's Blog

Threat Score
92/100

Date Published: 2026-05-23

Date Updated: 2026-07-24

...
...

A supply-chain attack was discovered on May 22, 2026 targeting laravel-lang repositories: attackers published 233 malicious version tags that point to commits in a malicious fork, adding a PHP dropper (src/helpers.php) which fetches a large credential-stealing payload from flipboxstudio.info that exfiltrates cloud, infrastructure, developer, browser, password-manager and cryptocurrency wallet secrets; Packagist removed the malicious versions and the report provides IOCs and remediation/detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.