news.mlab.sh
Back to the feed
malware

Laravel Lang packages hijacked to deploy credential-stealing malware

High
Summary

A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, downloaded a cross-platform credential stealer named 'DebugElevator' that targeted browser data, secrets, and configuration files. Security firms responded quickly by removing the malicious versions from Packagist, advising developers to review their installations and implement security measures.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.