Laravel Lang packages hijacked to deploy credential-stealing malware

2026-05-24T13:23:28Zbb6ae140ea040e9edfeddec94403080a379417afa2d963a47688a5b3cde6cd3e
apex-onebotnetchromiumcinemagoalcisco-secure-workloadcomposercredential-stealerdrupalgithub-tagshosting-abusejfmbackdoorkimwolflaravellaw-enforcement-takedownpiracyrceshowboatsql-injectionsupply-chaintelco-targetingubiquitiunifi-osvpn-seizurezero-day

What happened

Multiple high-risk incidents reported across open-source supply chain, enterprise, and ISP/hosting ecosystems. Attackers hijacked Laravel Lang localization packages by abusing GitHub version tags to push malicious Composer releases that deploy credential‑stealing malware, exposing developers and CI environments. Multiple actively exploited and maximum‑severity flaws were disclosed/patched this week: an Apex One zero‑day (Trend Micro) being used in the wild, a critical Drupal SQL injection under attack, and max‑severity fixes for Ubiquiti UniFi OS and Cisco Secure Workload that allow remote/una

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
bb6ae140ea040e9edfeddec94403080a379417afa2d963a47688a5b3cde6cd3e
Enrichment time
2026-05-24T13:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.