MEDIUMSupply Chain
Global

Laravel Lang packages hijacked to deploy credential-stealing malware

·Source: BleepingComputer

Updated:

Executive Summary

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]

Analysis

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]
Source Attribution

Originally published by BleepingComputer on May 23, 2026.

Related Threats