Frequency
3
occurrences
First Seen
May 23, 2026
Last Seen
June 26, 2026
Related Threat Clusters
-
Supply Chain Attack Compromises Laravel Lang Packages with Credential Stealer
On May 22, 2026, a supply chain attack targeted Laravel Lang localization packages, compromising 233 versions across four repositories. Attackers exploited GitHub's version tagging system to redirect legitimate tags to…
17 articles · Updated May 23, 2026 -
New Malware Blocking Features Implemented in Composer 2.10 and Private Packagist
On June 26, 2026, Private Packagist announced enhancements to its malware blocking capabilities for Composer users, particularly those using version 2.10. The updates prevent the installation of flagged malware…
3 articles · Updated June 26, 2026
Recent Intelligence Reports
- Packagist is now protected by Aikido Intel and other updates to the PHP registry — Aikido.Dev · June 26, 2026
- Hackers Compromise Laravel — Gbhackers · May 23, 2026
- Supply Chain Attack Targets Laravel — Aikido.Dev · May 23, 2026
Related Entities
Malware
Supply Chain Attack
T1027 - Obfuscated Files Or Information
T1059 - Command and Scripting Interpreter
T1071 - Application Layer Protocol
T1105 - Ingress Tool Transfer
T1195 - Supply Chain Compromise
T1555.003 - Credentials From Web Browsers
T1567 - Exfiltration Over Web Service
Crates.io
GitHub
Linux