Laravel-Lang Composer tag-rewrite Supply Chain Attack
ID: 5f41aec1-da90-58f1-80f1-1943c38fd506
STIX ID: report--5f41aec1-da90-58f1-80f1-1943c38fd506
Feed Name: Security Boulevard
A tag‑rewrite supply‑chain attack (2026-05-22 into 2026-05-23) targeted four Laravel‑Lang Composer packages (laravel-lang/lang, attributes, http-statuses, actions), adding an autoload.files entry and src/helpers.php that executes on vendor/autoload.php. The helpers.php dropper fetches a stage‑two PHP credential stealer from https://flipboxstudio.info/payload, which harvests cloud metadata, Kubernetes tokens, Vault/Jenkins secrets, local process data, and developer credentials, XOR‑encrypts exfiltrated data, and posts to https://flipboxstudio.info/exfil; the report provides IOCs, analysis, and mitigation steps (block domain, audit/pin lockfiles to known-good SHAs, remove artifacts, rotate credentials).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
