Multiple Laravel-Lang packages were reportedly poisoned to distribute malware through the software supply chain, exposing developers and downstream environments that installed the compromised components. The incident affected a widely used localization package ecosystem for Laravel applications, turning trusted dependencies into a delivery mechanism for malicious code and raising concerns about package integrity in developer workflows.
The broader reporting context underscores continued pressure on organizations from software compromise, ransomware, and data theft incidents, but the clearest common event here is the package poisoning campaign targeting Laravel developers. The case highlights the risk that attackers can abuse legitimate repositories and trusted update paths to spread malware, making dependency verification, repository monitoring, and rapid package auditing critical for defenders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
SecurityWeek reported that a data breach at Radiology Associates of Richmond affected 266,000 individuals. This introduces a new victim disclosure and impact figure not previously captured in the timeline.
SecurityWeek reported that Laravel-Lang packages had been poisoned to deliver malware, indicating a software supply chain compromise affecting those packages. The reference points to public disclosure of the malicious package activity.
A SecurityWeek reference indicates GitHub confirmed a hack affecting 3,800 internal repositories. Because the provided content contains no substantive incident details beyond the headline, only the broad confirmation can be captured.
Acuity addressed claims about stolen US government data, stating that hackers obtained older, non-sensitive information. The statement represents the company's public response and characterization of the impact.
Xerox confirmed that a US subsidiary suffered a data breach following a ransomware attack. This marks the company's official acknowledgment of compromise and resulting data exposure.
SecurityWeek reported that food giant Kraft Heinz had been targeted by a ransomware group. The reference establishes the company as a victim of a ransomware-related incident.
Fidelis Security published an overview of Apache ActiveMQ vulnerability CVE-2023-46604, marking public technical discussion of the flaw and its security implications. The reference indicates disclosure and analysis of the vulnerability rather than a specific victim incident.
Dragos disclosed that a ransomware group had obtained limited data from the company but that an elaborate extortion attempt did not succeed. The report indicates the incident did not result in the broader impact the attackers sought.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcesecurityweek.com
Open sourcesecurityweek.com
Open sourcesecurityweek.com
Open sourcesecurityweek.com
Open sourcesecurityweek.com
Open sourcesecurityweek.com
Open sourcefidelissecurity.com
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.