Signal

Laravel Lang packages compromised in supply chain attack deploying credential-stealing malware

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-23 09:51 UTCUpdated 2026-05-23 20:48 UTC
rss
supply_chainmalwarecredential_stealingphpcomposerpackagist
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Laravel Lang Supply Chain Advisory
Snyk Blog · News · snyk.io · 2026-05-23 16:00 UTC
Overview

A coordinated supply chain attack has targeted multiple Laravel Lang PHP packages, republishing hundreds of releases with malicious code that steals credentials and exfiltrates secrets.

Entities
Laravel LangGitHubPackagistComposer
Score total
1.4
Momentum 24h
4
Posts
4
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Attackers exploited GitHub version tags to republish hundreds of Laravel Lang releases with malware.
  • Multiple packages were compromised simultaneously, indicating a coordinated campaign.
  • Recent infections include Linux malware targeting JavaScript projects via Packagist packages.
Why it matters
  • Supply chain attacks on popular PHP packages risk widespread credential theft and secret exfiltration.
  • Malicious code distribution via trusted package managers undermines developer trust and software integrity.
  • Early detection and mitigation are critical to protect dependent projects and infrastructure.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Laravel Lang PHP packages were compromised to deliver credential-stealing malware via republished releases.
  • Eight Packagist packages were infected with Linux malware distributed through GitHub-hosted binaries, inserted into package.json files.
How sources frame it
  • BleepingComputer: neutral
  • The Hacker News: neutral
  • Snyk Blog: neutral
All evidence
All evidence
Laravel Lang packages hijacked to deploy credential-stealing malware
bleepingcomputer_all · bleepingcomputer.com · 2026-05-23 20:48 UTC
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
thehackernews · thehackernews.com · 2026-05-23 16:07 UTC
Laravel Lang Supply Chain Advisory
Snyk Blog · snyk.io · 2026-05-23 16:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • bleepingcomputer_all (1)
  • thehackernews (1)
  • Snyk Blog (1)
Top origin domains (this list)
  • bleepingcomputer.com (1)
  • thehackernews.com (1)
  • snyk.io (1)