Laravel Lang packages hijacked to deploy credential-stealing malware
2026-05-24T13:23:28Z•bb6ae140ea040e9edfeddec94403080a379417afa2d963a47688a5b3cde6cd3e
apex-onebotnetchromiumcinemagoalcisco-secure-workloadcomposercredential-stealerdrupalgithub-tagshosting-abusejfmbackdoorkimwolflaravellaw-enforcement-takedownpiracyrceshowboatsql-injectionsupply-chaintelco-targetingubiquitiunifi-osvpn-seizurezero-day
What happened
Multiple high-risk incidents reported across open-source supply chain, enterprise, and ISP/hosting ecosystems. Attackers hijacked Laravel Lang localization packages by abusing GitHub version tags to push malicious Composer releases that deploy credential‑stealing malware, exposing developers and CI environments. Multiple actively exploited and maximum‑severity flaws were disclosed/patched this week: an Apex One zero‑day (Trend Micro) being used in the wild, a critical Drupal SQL injection under attack, and max‑severity fixes for Ubiquiti UniFi OS and Cisco Secure Workload that allow remote/una
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- bb6ae140ea040e9edfeddec94403080a379417afa2d963a47688a5b3cde6cd3e
- Enrichment time
- 2026-05-24T13:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.