Security Feed
  1. Archives

May 23 2026 Laravel Lang packages hijacked to deploy credential-stealing malware

Source

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]

Posted by Lawrence Abrams on Sat 23 May 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Microsoft
  • Security Blog
  • Biz & IT
  • AI
  • Security & Identity
  • CryptoCurrency
  • google
  • Announcements
  • Artificial Intelligence
  • Foundational (100)
  • Legal
  • A Little Sunshine
  • Privacy
  • Apple
  • squid
  • Mobile
  • Hacking
  • Intermediate (200)
  • Advanced (300)
  • LLM
  • Technical How-to
  • vulnerabilities

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.