216.73.217.22

Laravel Lang Compromised with RCE Backdoor Across 700+ Versions

· Published 23/05/2026 10:56 · Modified 25/05/2026 10:51

Export JSON

Essential information

Published
23/05/2026 10:56
Modified
25/05/2026 10:51
Tags
2026-05-23 developer compromise information stealer laravel rce backdoor supply chain attack
Related entities
2 observables, 19 techniques (mitre), 2 malware, 1 others

Description

Community-maintained Lang packages were compromised with remote code execution backdoors affecting over 700 versions across multiple repositories including -lang/lang, -lang/http-statuses, -lang/attributes, and -lang/actions. The attack involved coordinated rapid tag publishing on May 22-23, 2026, suggesting organization-level credential compromise. A malicious helpers.php file was automatically executed via Composer's autoloader, deploying a sophisticated cross-platform . The second-stage payload systematically harvested credentials from cloud infrastructure, Kubernetes, CI/CD systems, browsers, password managers, cryptocurrency wallets, VPN clients, and local configurations. Stolen data was encrypted and exfiltrated to a command-and-control server. The backdoor employed advanced evasion techniques including TLS verification bypass, per-host execution markers, and embedded Windows executables to bypass Chrome encryption protections.

External references