Vulnerabilities · 112 days ago
The break is not just that a Composer package was malicious. It is that Packagist’s tag-to-GitHub resolution let attackers republish old laravel-lang releases after the fact, so a version number no longer proves the package came from the original source. That makes normal trust checks on historical tags unreliable, even when the release looks old and legitimate.
Researchers saw 700+ laravel-lang tags mass-republished on May 22–23 across laravel-lang/lang, http-statuses, attributes, and actions. The poisoned releases carried an autoloaded helpers.php that contacted flipboxstudio[.]info and dropped a cross-platform credential stealer, exposing cloud, CI/CD, SSH, Vault, browser, password manager, and wallet secrets in Composer-based builds and requests.
The risk persists after the repo looks clean. Any environment that installed one of the poisoned releases may have already executed the backdoor at install or request time, and the stolen secrets can outlive the package compromise itself.
5 sources covering this story
Laravel-Lang Packages Poisoned for Malware Delivery
Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets.
Laravel Lang packages hijacked to deploy credential-stealing malware
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages.
Laravel Lang Supply Chain Advisory | Snyk
Laravel Lang Packagist releases were republished with malicious code.
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Laravel-Lang compromise tagged 700+ versions on May 22–23, 2026, triggering PHP stealers that exfiltrate credentials.
Laravel Lang Compromised with RCE Backdoor Across 700+ Versi...
Laravel Lang packages were compromised with an RCE backdoor across hundreds of versions, exposing cloud, CI/CD, and developer secrets.
Part of the PlainSec briefing for 2026-05-24