Laravel Lang packages hijacked to deploy credential-stealing malware

2026-05-24T01:23:27Z554bccd1b34fc3b84527392f822244ec89add23e25c2e6a5c0e42525cc03ace9
active-exploitationapex-oneauth-code-theftchromiumcinemagoalciscocomposercredential-stealerdrupalgithub-tag-abusehosting-abuselaravel-langlaw-enforcement-takedownmalwarenetherlands-fiodpackage-hijackprivilege-escalationrce-leaksecure-workloadsql-injectionstreaming-piracysupply-chainubiquitiunifi-oszero-day

What happened

Aggregated BleepingComputer headlines (21–23 May 2026): A supply‑chain attack hijacked Laravel Lang localization packages by abusing GitHub version tags to push malicious Composer packages that deploy credential‑stealing malware targeting developers. Other notable incidents include Italian takedown of the CINEMAGOAL piracy app that stole streaming authentication codes; Netherlands FIOD seizure of 800 servers from a hosting firm facilitating cyberattacks and disinformation; Trend Micro warning of an Apex One zero‑day exploited in the wild; active exploitation attempts against a critical Drupal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
554bccd1b34fc3b84527392f822244ec89add23e25c2e6a5c0e42525cc03ace9
Enrichment time
2026-05-24T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Laravel Lang packages hijacked to deploy credential-stealing malware · Baitaphish