Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
aikido.dev | incident | #cloud | #supply-chain | #credential-theft | #php | #supply-chain-security | #laravel | #composer | #incident
Summary
233 versions across three Laravel-Lang repositories were compromised via malicious tags pointing to attacker fork commits, loading a PHP credential stealer through Composer's autoloader.
- Published
- Collected
Skip to content