Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Claude Mythos AI finds 10,000 high-severity flaws in widely used software

Laravel-Lang PHP package compromised to deliver cross-platform credential stealer

LiteSpeed ​​cPanel plugin CVE-2026-48172 can be exploited to execute scripts as root.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Laravel-Lang PHP package compromised to deliver cross-platform credential stealer
Identity

Laravel-Lang PHP package compromised to deliver cross-platform credential stealer

By May 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 23, 2026Supply chain attacks/malware

Cybersecurity researchers have warned of a new software supply chain attack campaign targeting multiple PHP packages belonging to Laravel-Lang to provide a comprehensive credential theft framework.

Affected packages include:

laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions

“The timing and pattern of the newly published tags indicate a broader compromise of the Laravel Lang organization’s release process, rather than a single malicious package version,” Socket said. “The tags were published in quick succession on May 22 and May 23, 2026, with many versions published just seconds apart.”

Over 700 versions associated with these packages have been identified, indicating a large amount of automated tagging or republishing. It is suspected that the attackers may have gained access to organization-level credentials, repository automation, or release infrastructure.

The core malicious functionality is located in a file named “src/helpers.php” embedded in the version tag. It is primarily designed to fingerprint infected hosts and connect to an external server (‘flipboxstudio’).[.]info”) to get a PHP-based cross-platform payload that runs on Windows, Linux, and macOS.

According to Aikido Security, this dropper provides a Visual Basic Script launcher on Windows and runs via cscript. On Linux and macOS, execute stealer payloads via exec().

“Because this file [‘src/helpers.php’] Once registered in composer.json under autoload.files, the backdoor will automatically run on every PHP request processed by a compromised application,” Socket explained.

“This script generates a unique marker for each host (an MD5 hash combining directory path, system architecture, and inode) to ensure that the payload is only triggered once per machine. This prevents redundant execution and allows the malware to remain undetected after the first execution.”

This stealer has the ability to collect a wide range of data from a compromised system and exfiltrate it to the same server. This includes –

IAM Roles and Instance IDs by Querying Cloud Metadata Endpoints Documentation Default Credentials for Google Cloud Applications Microsoft Azure Access Tokens and Service Principal Profiles Kubernetes Service Account Tokens and Helm Registry Configuration Authentication Tokens for DigitalOcean, Heraku, Vercel, Netlify, Railway, Fly.io HashiCorp Vault Tokens Jenkins, GitLab Runners, GitHub Tokens and configuration actions from CircleCI, TravisCI, ArgoCD Seed phrases and files associated with cryptocurrency wallets (Electrum, Exodus, Atomic, Ledger Live, Trezor, Wasabi, Sparrow) and extensions (MetaMask, Phantom, Trust Wallet, Ronin, Keplr, Solflare, Rabby) Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, Opera Browser history, cookies, and login data Use of built-in Base64-encoded Windows executables that bypass Chromium’s App-Binding Encryption (ABE) protection Local vault and browser extension data for 1Password, Bitwarden, LastPass, KeePass, Dashlane, and NordPass PuTTY/WinSCP saved sessions Dump Windows Credential Manager’s WinSCP saved sessions RDP files Session tokens associated with applications such as Discord, Slack, and Telegram Data from Microsoft Outlook, Thunderbird, and popular FTP clients (FileZilla, WinSCP, and CoreFTP) Configuration and credential files including Docker authentication tokens, SSH private keys, Git credentials, shell history files, database history files, Kubernetes cluster configuration, .env files, wp-config.php, and docker-compose.yml PHP Environment variables loaded into the process Source control credentials from global and local .gitconfig files, .git-credentials, and .netrc files VPN configuration and saved login files for OpenVPN, WireGuard, NetworkManager, and commercial VPNs such as NordVPN, ExpressVPN, CyberGhost, and Mullvad

“The fetched payload is approximately 5,900 lines of PHP credential stealer organized into 15 specialized collector modules,” said Aikido researcher Ilyas Makari. “After we collect everything we find, we encrypt the results with AES-256 and send them to flipboxstudio.[.]info/exfil. It then deletes itself from disk to limit forensic evidence. ”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLiteSpeed ​​cPanel plugin CVE-2026-48172 can be exploited to execute scripts as root.
Next Article Claude Mythos AI finds 10,000 high-severity flaws in widely used software

Related Posts

Claude Mythos AI finds 10,000 high-severity flaws in widely used software

May 23, 2026

LiteSpeed ​​cPanel plugin CVE-2026-48172 can be exploited to execute scripts as root.

May 23, 2026

Drupal core SQL injection bug actively exploited and added to CISA KEV

May 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Claude Mythos AI finds 10,000 high-severity flaws in widely used software

Laravel-Lang PHP package compromised to deliver cross-platform credential stealer

LiteSpeed ​​cPanel plugin CVE-2026-48172 can be exploited to execute scripts as root.

Drupal core SQL injection bug actively exploited and added to CISA KEV

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.