Vulnerabilità · 129 giorni fa
La rottura non è solo che un package Composer fosse malevolo. È che la risoluzione tag-to-GitHub di Packagist ha consentito agli attaccanti di ripubblicare a posteriori vecchie release di laravel-lang, così un numero di versione non prova più che il package provenisse dalla fonte originale. Questo rende inaffidabili i normali controlli di fiducia sui tag storici, anche quando la release sembra vecchia e legittima.
5 fonti che coprono questa storia
Laravel-Lang Packages Poisoned for Malware Delivery
Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.
Laravel Lang packages hijacked to deploy credential-stealing malware
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages.
Laravel Lang Supply Chain Advisory | Snyk
Laravel Lang Packagist releases were republished with malicious code.
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Laravel-Lang compromise tagged 700+ versions on May 22–23, 2026, triggering PHP stealers that exfiltrate credentials.
Laravel Lang Compromised with RCE Backdoor Across 700+ Versi...
Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets.
Part of the PlainSec briefing for 2026-05-24