Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Incidents: Laravel-Lang PHP packages compromised to deliver a cross-platform credential stealer via automated mass republishing of malicious versions.
Deep Analysis and Expert Commentary
The attack leverages the autoload.files feature in composer.json to ensure the malicious 'src/helpers.php' executes on every PHP request, bypassing the need for manual triggers. This technique exploits the trust in package dependencies and the widespread use of Laravel and Symfony frameworks. The payload's modular design allows it to collect credentials from diverse sources, including cloud services, CI/CD pipelines, and local storage. Mitigations include auditing package versions, monitoring for unusual autoload.files entries, and restricting outbound connections to known malicious domains like flipboxstudio[.]info. Organizations should also enforce MFA for repository access and implement automated dependency scanning.
Action Items
- Audit and revert to known-good versions of affected Laravel-Lang packages.
- Monitor and block outbound connections to flipboxstudio[.]info and other suspicious domains.
- Enforce MFA and review access controls for repository automation tools.
Original Article Brief Intro
The Hacker News · 2026-05-23 · Incidents: Laravel-Lang PHP packages compromised to deliver a cross-platform credential stealer via automated mass republishing of malicious versions.
Related Terms and Notes
Malware Families
- credential_stealer
Techniques / TTPs
- credential theft
- supply chain attack
Context Notes
- autoload.files — A Composer feature that automatically loads specified files when the application boots.
- Laravel
- Laravel-Lang — A collection of PHP packages providing localization support for Laravel applications.
- PHP
- PHP packages
- supply_chain