logo

Laravel Lang packages hijacked to deploy credential-stealing malware

ID: cb4b9276-5db2-59fa-b58c-4d0cc3ddc965

STIX ID: report--cb4b9276-5db2-59fa-b58c-4d0cc3ddc965

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Lawrence Abrams

...
...

A supply-chain attack against multiple Laravel Lang Composer packages abused GitHub tag rewriting to distribute malicious releases that autoloaded a dropper (src/helpers.php). The dropper downloaded a large cross-platform credential stealer from an attacker-controlled C2 (flipboxstudio.info) that harvests cloud credentials, Kubernetes secrets, Git/CI tokens, SSH keys, browser data and other secrets; on Windows it drops and runs a credential-stealing binary called DebugElevator. Security firms reported hundreds of historical versions impacted, Packagist removed the malicious versions, and developers are advised to audit installed versions, rotate exposed credentials, and investigate potential indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.