Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Found in Laravel-Lang Composer Packages

Malware Found in Laravel-Lang Composer Packages

Posted on May 25, 2026 By CWS

Security researchers have identified a significant security breach affecting several Composer packages managed by the Laravel-Lang organization. Hackers successfully inserted malware into these packages by altering all their Git tags, posing a severe threat to applications utilizing these third-party localization libraries.

Details of the Compromised Packages

The targeted packages include laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. These are widely used in Laravel applications for localization purposes. The breach was initiated on May 22, with malicious version tags being published within a 15-minute window. By midnight UTC on May 23, all four packages had been compromised, according to StepSecurity.

Mechanism of the Malicious Attack

The attack did not involve direct modifications to the official repositories. Instead, attackers exploited GitHub’s version tagging system to point tags to commits from a malicious fork. This method allowed the spread of malware across over 700 historical versions of the packages, potentially affecting any application updating or freshly installing them.

The infected tags included a file named src/helpers.php, disguised as a Laravel localization helper. This file identifies the machine’s environment and connects to a command-and-control domain to download a PHP credential stealer, which executes clandestinely.

Consequences and Mitigation Strategies

The implanted malware is designed to extract sensitive data such as cloud service keys, Docker and Kubernetes setups, developer credentials, and more from affected systems. It also targets browser-stored credentials, cryptocurrency wallets, and various configuration files across different operating systems.

Organizations are advised to block the affected packages immediately and consider any systems that utilized them as potentially compromised. Verification of clean package versions and their subsequent installation is crucial. Additionally, it is recommended to rotate any exposed secrets and credentials that may reside on affected hosts or developer environments.

In light of this incident, it underscores the importance of vigilance in software supply chains and the need for robust security measures to protect sensitive data and systems.

Security Week News Tags:cloud security, command-and-control, Composer packages, credential theft, Cybersecurity, data breach, developer tools, Git tags, Laravel, Laravel-Lang, Malware, PHP, Software Security, supply chain attack, version control

Post navigation

Previous Post: Iranian Hackers Exploit Azure for Espionage Campaigns

Related Posts

Apple Seeks Researchers for 2026 iPhone Security Program Apple Seeks Researchers for 2026 iPhone Security Program Security Week News
Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Security Week News
TrustCloud Raises  Million for Security Assurance Platform TrustCloud Raises $15 Million for Security Assurance Platform Security Week News
Wide Range of Malware Delivered in React2Shell Attacks Wide Range of Malware Delivered in React2Shell Attacks Security Week News
Security Flaws in Perforce Servers Risk Sensitive Data Security Flaws in Perforce Servers Risk Sensitive Data Security Week News
Mythos AI Uncovers Minor Curl Flaw, Sparks Expert Debate Mythos AI Uncovers Minor Curl Flaw, Sparks Expert Debate Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malware Found in Laravel-Lang Composer Packages
  • Iranian Hackers Exploit Azure for Espionage Campaigns
  • DocketWise Data Breach Exposes 143,000 Users’ Information
  • CypherLoc Kit Traps Users with Fake Microsoft Support Calls
  • Megalodon Attack Infects Over 5,500 GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malware Found in Laravel-Lang Composer Packages
  • Iranian Hackers Exploit Azure for Espionage Campaigns
  • DocketWise Data Breach Exposes 143,000 Users’ Information
  • CypherLoc Kit Traps Users with Fake Microsoft Support Calls
  • Megalodon Attack Infects Over 5,500 GitHub Repositories

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark