Safedep • 14w
Supply Chain Compromise of Laravel-Lang Localization Packages: Cross-Platform Credential Theft and RCE
A massive supply chain attack has compromised the Laravel-Lang localization ecosystem, injecting malicious payloads into over 700 historical package versions. This breach enables automated credential theft and remote code execution via Composer, posing a critical threat to both developer environments and production infrastructure.