Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Found in Laravel-Lang Composer Packages

Malware Found in Laravel-Lang Composer Packages

Posted on May 25, 2026 By CWS

Security researchers have identified a significant security breach affecting several Composer packages managed by the Laravel-Lang organization. Hackers successfully inserted malware into these packages by altering all their Git tags, posing a severe threat to applications utilizing these third-party localization libraries.

Details of the Compromised Packages

The targeted packages include laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. These are widely used in Laravel applications for localization purposes. The breach was initiated on May 22, with malicious version tags being published within a 15-minute window. By midnight UTC on May 23, all four packages had been compromised, according to StepSecurity.

Mechanism of the Malicious Attack

The attack did not involve direct modifications to the official repositories. Instead, attackers exploited GitHub’s version tagging system to point tags to commits from a malicious fork. This method allowed the spread of malware across over 700 historical versions of the packages, potentially affecting any application updating or freshly installing them.

The infected tags included a file named src/helpers.php, disguised as a Laravel localization helper. This file identifies the machine’s environment and connects to a command-and-control domain to download a PHP credential stealer, which executes clandestinely.

Consequences and Mitigation Strategies

The implanted malware is designed to extract sensitive data such as cloud service keys, Docker and Kubernetes setups, developer credentials, and more from affected systems. It also targets browser-stored credentials, cryptocurrency wallets, and various configuration files across different operating systems.

Organizations are advised to block the affected packages immediately and consider any systems that utilized them as potentially compromised. Verification of clean package versions and their subsequent installation is crucial. Additionally, it is recommended to rotate any exposed secrets and credentials that may reside on affected hosts or developer environments.

In light of this incident, it underscores the importance of vigilance in software supply chains and the need for robust security measures to protect sensitive data and systems.

Security Week News Tags:cloud security, command-and-control, Composer packages, credential theft, Cybersecurity, data breach, developer tools, Git tags, Laravel, Laravel-Lang, Malware, PHP, Software Security, supply chain attack, version control

Post navigation

Previous Post: Iranian Hackers Exploit Azure for Espionage Campaigns
Next Post: Rise in Scans Targeting SonicWall Firewall Interfaces

Related Posts

ASOS Hit by Cyberattack Compromising User Data ASOS Hit by Cyberattack Compromising User Data Security Week News
Edamame’s New System Tackles AI Code Drift Edamame’s New System Tackles AI Code Drift Security Week News
US Sentences Two for North Korean IT Scheme Involvement US Sentences Two for North Korean IT Scheme Involvement Security Week News
Critical Dialogflow CX Flaw Exposed AI Conversations Critical Dialogflow CX Flaw Exposed AI Conversations Security Week News
New ‘Broadside’ Botnet Poses Risk to Shipping Companies New ‘Broadside’ Botnet Poses Risk to Shipping Companies Security Week News
Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk Spectre v2 Variant Puts Intel, AMD, Arm CPUs at Risk Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Compromised Tensorlake npm Package Delivers Credential-Stealing Malware
  • Claude Haiku 5.5: Affordable AI Model for Enhanced Efficiency
  • Elastic Addresses Critical Security Vulnerabilities
  • FBI Warns of Global FortiBleed Cyber Threat
  • Hackers Exploit Websites with Fake Cloudflare Pages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Compromised Tensorlake npm Package Delivers Credential-Stealing Malware
  • Claude Haiku 5.5: Affordable AI Model for Enhanced Efficiency
  • Elastic Addresses Critical Security Vulnerabilities
  • FBI Warns of Global FortiBleed Cyber Threat
  • Hackers Exploit Websites with Fake Cloudflare Pages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark