A supply-chain attack hit the Laravel-Lang ecosystem after attackers rewrote Git tags across laravel-lang/lang, laravel-lang/attributes, laravel-lang/http-statuses, and related repositories, causing 233 tagged package versions to resolve to malicious commits. Researchers said the attacker abused GitHub tags that pointed to forked commits rather than altering the visible upstream code, allowing poisoned releases to spread through Composer and Packagist; one report said roughly 700 GitHub repositories were affected. Packagist removed the malicious versions and temporarily unlisted the impacted packages to stop further installs.
The malicious packages added src/helpers.php through Composer's autoload.files, so code executed automatically when applications loaded vendor/autoload.php in common PHP workflows including Laravel, Symfony, PHPUnit, and CI runners. The payload contacted flipboxstudio.info, dropped follow-on malware, and stole secrets including cloud credentials, CI environment variables, developer tokens, SSH keys, browser passwords, cryptocurrency wallets, VPN data, and Windows-specific credentials before encrypting and exfiltrating the data and deleting artifacts to hinder forensics. Security firms urged organizations that installed affected packages after the compromise to treat those environments as breached, rotate all accessible secrets, inspect composer.lock files, monitor for suspicious outbound traffic, and rebuild compromised systems from known-good images.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-23, multiple security researchers and outlets publicly reported the supply chain attack, describing how attackers poisoned Laravel-Lang package versions across hundreds of GitHub-tagged releases. The disclosures warned defenders to inspect composer.lock files, treat systems installing affected packages after the compromise window as potentially compromised, and rotate exposed secrets.
After the malicious Laravel-Lang versions were identified, Packagist removed the poisoned releases and temporarily unlisted the affected packages to stop further installations. This response was reported by Aikido in coverage published on 2026-05-23.
On 2026-05-22, StepSecurity reproduced the compromise in an isolated GitHub Actions runner for laravel-lang/http-statuses v3.4.5 and observed exfiltration of runner environment data along with cleanup behavior that deleted on-disk artifacts while leaving orphaned processes in memory. The company assessed the other affected packages as likely behaving the same because of their matching malicious commit structure.
The poisoned package versions added a backdoored src/helpers.php via Composer autoload.files so code executed automatically when the packages were installed or autoloaded. The malware contacted flipboxstudio.info, deployed a dropper and second-stage stealer, collected secrets such as cloud credentials, developer tokens, SSH keys, browser passwords, wallet data, and other infrastructure secrets, then encrypted and exfiltrated the data.
On 2026-05-22, a threat actor compromised Laravel-Lang Composer packages by force-rewriting existing Git tags to point to malicious commits, abusing GitHub tags rather than committing directly to the official upstream repositories. Reports indicate the affected repositories included laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/lang/actions-related packages, with 233 tagged versions impacted across the ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcexakep.ru
Open sourcephoenix.security
Open sourcethreats.wiz.io
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.