Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitHub Down: Authentication Issues Deny Access to Actions
May 26, 2026
Hackers Exploit Ghost CMS CVE-2026 CVE-2026-26980 Poison
May 26, 2026
NightSpire Ransomware Leverages RDP & Admin Uses Access
May 26, 2026
Home/CyberSecurity News/Hackers Compromised 233 Laravel-Lang Versions Packages
CyberSecurity News

Hackers Compromised 233 Laravel-Lang Versions Packages

A highly sophisticated supply chain attack compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub...

Sarah simpson
Sarah simpson
May 23, 2026 2 Min Read
20 0

A highly sophisticated supply chain attack compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories.

Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to distribute malware through Composer’s autoloader, granting complete remote access to developer environments.

The attackers bypassed direct repository commits by exploiting GitHub’s version tagging system to point legitimate tags toward a malicious fork.

When developers pulled the affected localization packages via Packagist, the malicious src/helpers.php executed automatically due to Composer’s autoload.files directive. This method effectively hid the malware from standard repository audits while inheriting full web application permissions.

The initial infection phase utilizes a stealthy dropper that masquerades as a standard Laravel localization function. It fingerprints the host system using specific hardware metrics and establishes a temporary marker file to prevent redundant executions.

Aikido observed that the payload disables SSL verification and fetches a secondary script from an obfuscated command-and-control server, launching it silently via OS-specific methods.

Payload Execution Methods

Operating System Execution Mechanism Privilege Level
Linux Background execution using exec("php ...") Application user
macOS Background execution using exec("php ...") Application user
Windows Generated .vbs script running via cscript Application user

The fetched payload is an extensive PHP credential stealer containing 15 specialized collector modules. It systematically targets sensitive developer secrets, including cloud metadata, database credentials, and environment configuration files.

After harvesting the secrets, the malware encrypts the payload using AES-256 and exfiltrates it to the attacker’s infrastructure before deleting itself to evade forensic detection.

The malware framework systematically strips the infected machine of high-value configurations and credentials:

  • Cloud access keys for AWS, GCP, Azure, and DigitalOcean.
  • Infrastructure configurations including Kubernetes profiles, Docker tokens, and HashiCorp Vault secrets.
  • Developer assets such as SSH private keys, Git credentials, and shell history files.
  • Saved browser passwords, cryptocurrency wallets, and password manager databases.

Security researchers advise immediate rotation of all application secrets, database credentials, and API keys exposed to compromised environments.

Development teams must inspect their composer.lock files to block affected Laravel-Lang packages and audit outbound network traffic for suspicious connections.

Systems running compromised packages should be entirely rebuilt from known-good images to ensure total eradication of the persistent threat.

Indicators of Compromise

Type Indicator
Domain (C2) flipboxstudio[.]info
URL (Payload Fetch) https://flipboxstudio[.]info/payload
URL (Exfiltration) https://flipboxstudio[.]info/exfil
File Path (Malicious) src/helpers.php
File Path (Infection Marker) <tmp>/.laravel_locale/<md5_hash>
File Path (Dropped Stealer) <tmp>/.laravel_locale/<12 random hex chars>.php
File Path (Windows Launcher) <tmp>/.laravel_locale/<8 random hex chars>.vbs
Artifact (Windows) DebugChromium.exe
IP Address 169.254.169.254
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in

Next Post

Hackers Exploit F5 BIG-IP to Gain SSH Appliance Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ConnectWise Automate Flaw Lets Attackers Bypass Vulnerability Security
May 26, 2026
Apache CXF LDAP Injection Allows Arbitrary Certificate Theft
May 26, 2026
Critical Memcached SASL Flaw Exposes Valid Vulnerability Attackers
May 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Sarah simpson
Sarah simpson
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us