Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets
On May 22, 2026, an attacker with push access to the Laravel-Lang GitHub organization rewrote git tags across multiple Composer packages to distribute malicious payloads that exfiltrate CI secrets. The attack affected laravel-lang/http-statuses, laravel-lang/actions, and laravel-lang/attributes, targeting developers who ran composer update or fresh installations.
- Disclosed
- Last updated
- Blast radius
- Multiple popular Composer packages in the Laravel-Lang organization; any developer running composer update or fresh installs of affected packages
- Ecosystems
- Attack vectors
- Affected entities
- laravel-lang/http-statuses
- laravel-lang/actions
- laravel-lang/attributes
On May 22, 2026, an attacker compromised the Laravel-Lang GitHub organization and exploited push access to rewrite git tags across multiple popular Composer packages within a 15-minute window. The compromised packages—laravel-lang/http-statuses, laravel-lang/actions, and laravel-lang/attributes—were modified to include malicious payloads designed to steal CI secrets.
The malicious payloads were configured to exfiltrate stolen CI secrets to a typosquatted attacker-controlled domain. Any developer running composer update or performing fresh installations against the affected packages would pull the compromised versions automatically.
StepSecurity confirmed end-to-end exploitation in an isolated runner environment and filed security issues across all affected repositories. The attack demonstrates the severe risk of account compromise within high-trust package maintainer accounts, where a single compromised credential can affect thousands of downstream consumers.
Remediation
- Revoke and regenerate any CI secrets (API keys, tokens, credentials) that may have been exposed
- Audit all CI/CD workflows and recent actions for unauthorized access or exfiltration
- Update to patched versions of laravel-lang/http-statuses, laravel-lang/actions, and laravel-lang/attributes once released
- Enable two-factor authentication (2FA) and review access controls for high-privilege accounts in the Laravel-Lang GitHub organization
- Review git history and tags across all Laravel-Lang repositories for other unauthorized changes
- Consider signing commits and tags with GPG to detect future tampering
- Monitor for any connections to the typosquatted attacker domain mentioned in the incident report
Sources
Cite this entry
"Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 22, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/laravel-lang-supply-chain-attack-every-tag-across-multiple-composer-packages-rew-h0akan
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in jest-canvas-mock (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in mcp-mermaid (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/li-editor (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-mock-data (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit