Laravel Lang Packages Hijacked Credential-Stealing Malware | MSSP Advisory
HighCredible Report
DateMay 23, 2026
📋Executive Summary
Attackers hijacked the Laravel Lang localization packages on Packagist by exploiting GitHub version tags to distribute credential-stealing malware through Composer package manager. The malware targets browser credentials, cookies, and authentication data from infected developer workstations. Multiple versions of the compromised packages were downloaded thousands of times before discovery.
⚠️Why It Matters for MSSPs
Your development team likely uses Composer packages in custom client applications, making your shop a direct target for credential theft that could expose client access tokens and authentication data. Every Laravel application you maintain for clients creates an advisory obligation because this supply chain attack specifically targets the development pipeline that builds their custom solutions.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Supply Chain
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.