Isometric network nodes showing Laravel Lang package credential theft.

Daily Cybersecurity News - May 24, 2026

Laravel Lang Packages Hijacked For Credential Theft

Attackers hijacked Laravel Lang localization packages on GitHub to push credential-stealing malware through Composer installs.

They abused version tags to inject malicious code that steals credentials from developer environments. The packages target Laravel projects and hit multiple developers before takedown.

This supply chain move is familiar in open-source but stands out for direct GitHub tag abuse instead of repo compromise. No overlap with known clusters yet.

The tag rewrites happened on May 22 and affected hundreds of versions across several Laravel-Lang packages.