PULSE NAME
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
WHITE PetrP.73 2026-05-25 Modified: 2026-05-25
3
IOCs
LOW VOLUME
On May 22, 2026, a supply chain attack was detected targeting the Laravel-Lang packages, which involved the injection of credential-stealing code into three popular repositories. The attacker cleverly deployed malicious version tags that pointed to a fork containing the hazardous code without committing it to the official repositories. This approach exploited GitHub's functionality allowing version tags to be linked to different commits, enabling the execution of malicious code via Composer's autoloader feature.
Indicators of Compromise (3)
All URL domain
TYPEINDICATORDESCRIPTIONCREATED
URL http://flipboxstudio.info/exfil 2026-05-25
URL http://flipboxstudio.info/payload 2026-05-25
domain flipboxstudio.info 2026-05-25