logo

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

ID: 5265682f-518b-5f08-b37c-4276f45dcaa5

STIX ID: report--5265682f-518b-5f08-b37c-4276f45dcaa5

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers observed a supply-chain compromise of multiple Laravel-Lang PHP packages where an autoloaded backdoor (src/helpers.php) was mass-tagged into releases and used to fetch a cross-platform PHP credential stealer that fingerprints hosts, executes automatically on each PHP request, harvests extensive cloud, VCS, browser, wallet and local credentials, encrypts results with AES-256 and exfiltrates them to flipboxstudio.info.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.