Laravel Lang packages hijacked to deploy credential-stealing malware
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...] Vendors: Microsoft, Google, AWS. DORA relevance: medium.
Por qué importa
Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.
Acción recomendada
Notify owners for Microsoft, Google, AWS technology stacks.
- Publicado
- 23 may 2026, 20:48
- Actualizado
- 23 may 2026, 21:00
- Detectado
- 23 may 2026, 21:00
- Fuente
- BleepingComputer
- Referencia técnica
- Original advisory


