logo

Laravel-Lang Composer tag-rewrite Supply Chain Attack

ID: 5f41aec1-da90-58f1-80f1-1943c38fd506

STIX ID: report--5f41aec1-da90-58f1-80f1-1943c38fd506

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Alina Podoba

...
...

A tag‑rewrite supply‑chain attack (2026-05-22 into 2026-05-23) targeted four Laravel‑Lang Composer packages (laravel-lang/lang, attributes, http-statuses, actions), adding an autoload.files entry and src/helpers.php that executes on vendor/autoload.php. The helpers.php dropper fetches a stage‑two PHP credential stealer from https://flipboxstudio.info/payload, which harvests cloud metadata, Kubernetes tokens, Vault/Jenkins secrets, local process data, and developer credentials, XOR‑encrypts exfiltrated data, and posts to https://flipboxstudio.info/exfil; the report provides IOCs, analysis, and mitigation steps (block domain, audit/pin lockfiles to known-good SHAs, remove artifacts, rotate credentials).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.