Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

    July 31, 2026

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026

    Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
    • Indigenous Fiber Network Connects Remote Subarctic Towns
    • Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance
    • A fundamental flaw leaves LLMs strikingly vulnerable to attack
    • IEEE Publishing Ethics Team Upholds Research Integrity
    • Why a Tiny Social Media Post Has Mathematicians Rethinking AI
    • Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic
    • Montana’s plan to become an experimental medical hub just pushed forward
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Laravel Lang packages hijacked to deploy credential-stealing malware
    Cybersecurity

    Laravel Lang packages hijacked to deploy credential-stealing malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 23, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hand sifting data
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages.

    Security firms StepSecurity, Aikido Security, and Socket warned about the compromise on Friday, warning that attackers had rewritten GitHub tags across four repositories maintained by the Laravel Lang organization rather than publishing entirely new malicious versions.

    The affected packages include laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and possibly laravel-lang/actions. The Laravel Lang packages are third-party localization packages and are not part of the official Laravel project.

    According to Aikido, the attackers compromised 233 versions across three repositories, while Socket said roughly 700 historical versions may have been impacted. 

    What made the attack stand out is that the actual project’s source code was not modified to include malicious code, but instead the attackers abused a GitHub feature that allows tags to point to commits in forks of the same repository.

    “Rather than publishing a new malicious version, the attacker rewrote every existing git tag in each repository to point at a new malicious commit,” explained StepSecurity.

    “The rewrites started at 22:32 UTC against laravel-lang/lang (the flagship Laravel translations package, with 502 tags) and finished by 00:00 UTC against laravel-lang/actions. All four repositories share the same fake author identity, the same modified files, and the same payload behavior, which makes them almost certainly the work of one actor using one compromised credential with org wide push access.”

    This allowed the attackers to publish what appeared to be legitimate release tags for the project, which actually led to malicious commits stored in an attacker-controlled fork of the repository.

    When developers installed the package via Composer, it would download the malicious code while it appeared to install legitimate Laravel Lang releases.

    Executes a credential-stealer

    The researchers found that the malicious releases introduced a malicious file named ‘src/helpers.php’, which was automatically loaded by Composer.

    helpers.php payload added to autoload section of composer.json

    The injected code acted as a dropper that downloaded a second payload from the attacker’s command and control server at flipboxstudio[.]info.

    The downloaded PHP payload [VirusTotal] was a large cross-platform credential stealer for Linux, macOS, and Windows that harvests cloud credentials, Kubernetes secrets, Vault tokens, Git credentials, CI/CD secrets, SSH keys, browser data, cryptocurrency wallets, password managers, VPN configurations, and local `.env` configuration files. 

    The malware also contains regular expression patterns used to extract AWS keys, GitHub tokens, Slack tokens, Stripe secrets, database credentials, JWTs, SSH private keys, and cryptocurrency recovery phrases from files and environment variables. 

    Regular expression patterns used to steal secrets
    Source: BleepingComputer

    On Windows systems, the PHP payload also extracts a base64-encoded executable [VirusTotal] embedded within the file, which is written to the %TEMP% folder as a random .exe filename, and then launched.

    BleepingComputer’s analysis of the Windows infostealer shows it is named ‘DebugElevator’ and designed to target Chrome, Brave, and Edge, and extract App-Bound Encryption keys needed to decrypt stored browser credentials.

    DebugElevator executable
    Source: BleepingComputer

    An embedded PDB path also references the Windows account name ‘Mero’ and contains ‘claude,’ potentially indicating that AI was used to assist in developing the Windows malware.


    C:\Users\Mero\OneDrive\Desktop\stuff\claude\Chromium-DebugElevator\x64\Release\DebugChromium.pdb

    The researchers say that once the sensitive data has been extracted, the malware encrypts it and sends it back to the C2 server.

    Aikido says they reported the incident to Packagist, which responded quickly by removing the malicious versions and temporarily unlisting the affected packages to prevent additional installations.

    Developers using Laravel Lang packages are advised to review installed package versions, rotate exposed credentials, inspect systems for indicators of compromise, and, if possible, check for historical outbound connections to flipboxstudio[.]info.

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now

    credentialstealing Deploy hijacked Lang Laravel malware packages
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
    • Indigenous Fiber Network Connects Remote Subarctic Towns
    • Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance
    • A fundamental flaw leaves LLMs strikingly vulnerable to attack
    • IEEE Publishing Ethics Team Upholds Research Integrity

    Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests

    July 31, 2026

    Indigenous Fiber Network Connects Remote Subarctic Towns

    July 31, 2026

    Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance

    July 31, 2026

    A fundamental flaw leaves LLMs strikingly vulnerable to attack

    July 31, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.