malware
Laravel Lang packages hijacked to deploy credential-stealing malware
High
Summary
A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, downloaded a cross-platform credential stealer named 'DebugElevator' that targeted browser data, secrets, and configuration files. Security firms responded quickly by removing the malicious versions from Packagist, advising developers to review their installations and implement security measures.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data