PULSE NAME
Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
WHITE AlienVault 2026-05-23 Modified: 2026-05-25
3
IOCs
LOW VOLUME
Community-maintained Laravel Lang packages were compromised with remote code execution backdoors affecting over 700 versions across multiple repositories including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. The attack involved coordinated rapid tag publishing on May 22-23, 2026, suggesting organization-level credential compromise. A malicious helpers.php file was automatically executed via Composer's autoloader, deploying a sophisticated cross-platform information stealer. The second-stage payload systematically harvested credentials from cloud infrastructure, Kubernetes, CI/CD systems, browsers, password managers, cryptocurrency wallets, VPN clients, and local configurations. Stolen data was encrypted and exfiltrated to a command-and-control server. The backdoor employed advanced evasion techniques including TLS verification bypass, per-host execution markers, and embedded Windows executables to bypass Chrome encryption protections.
Indicators of Compromise (1 / 3 total)
All URL domain
TYPEINDICATORDESCRIPTIONCREATED
domain flipboxstudio.info 2026-05-23