View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Laravel Lang packages hijacked to deploy credential stealer

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Laravel Lang packages hijacked to deploy credential-stealing malwareBleepingComputer A supply chain attack is actively abusing Laravel Lang localization packages distributed via Composer by manipulating GitHub version tags to push malicious updates. The injected payload is a sophisticated credential stealer targeting developer environments, risking compromised build systems and downstream applications. Immediate audit of Composer dependencies and lockfiles is advised, alongside monitoring for unusual outbound connections from development hosts.

📰 LESSER-KNOWN / UNDER-REPORTED

  • No additional new items at this time.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check