<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Four Laravel-Lang Packages Poisoned in Supply Chain Attack

Learn about the Laravel localization package breach affecting AWS, Azure keys, and more. Immediate action required for compromised systems.
Content Team

Four widely-used Laravel localization packages were compromised in a supply chain attack starting May 22. Hackers rewrote Git tags across over 700 historical versions of laravel-lang/lang, http-statuses, attributes, and actions — without ever touching the official repos. Instead, they pointed tags to commits in a malicious fork they controlled.

The malware connected to a C&C server to deploy a PHP credential stealer targeting AWS, GCP, Azure keys, SSH private keys, Kubernetes tokens, browser passwords, crypto wallets, and more — across Windows, Linux, and macOS.

Any system that installed or updated these packages should be treated as compromised, and all secrets rotated immediately.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo