Affected Systems

Multiple Laravel-Lang PHP packages compromised: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. Affects Laravel PHP applications using these localization packages. Specific malicious versions not detailed in provided data.

Exploitation Status

Active supply chain attack confirmed. Malicious packages published to distribution channels targeting Laravel ecosystem. Credential-stealing framework actively deployed through compromised package versions.

Business Impact

Applications using affected Laravel-Lang packages may have credential-stealing malware embedded in production environments. Attackers gain persistent access to steal authentication credentials, API keys, and sensitive data. Cross-platform nature suggests broad targeting of development and production systems. Immediate inventory and incident response required for Laravel applications using these localization packages.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately audit all Laravel applications for use of laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions packages
  • Check composer.lock files and installed package versions against known-good hashes from Laravel-Lang official repository
  • Rotate all credentials, API keys, and secrets accessible from systems running affected packages
  • Review application and system logs for unauthorized access or data exfiltration from timeframe when malicious packages were active
  • Update to verified clean versions of Laravel-Lang packages once vendor publishes remediation guidance and security advisories