logo

Supply Chain Storm: Over 700 Laravel Lang Versions Poisoned with Malicious RCE Backdoor

ID: b756e5df-2205-5728-9acb-2c8137021878

STIX ID: report--b756e5df-2205-5728-9acb-2c8137021878

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Ddos

...
...

Socket disclosed a widespread supply-chain compromise of the laravel-lang GitHub organization that injected RCE backdoors into ~700 historical localization package versions; the backdoor executes when Composer autoloads files and downloads a second-stage cross-platform info‑stealer with 17 collectors targeting cloud metadata, CI/CD secrets, Kubernetes tokens, wallets, and browser credentials. Immediate actions recommended include auditing composer.lock for laravel-lang packages, blocking or pinning dependencies, rotating all credentials and secrets, rebuilding hosts/CI runners from known-good images, and preserving logs and artifacts for forensic analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.