Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
Blog post from Socket
A compromise in the community-maintained Laravel Lang project has led to the insertion of remote code execution backdoors into several packages, including laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions, affecting over 700 historical versions. These are third-party localization packages used in Laravel applications but are not part of the official Laravel framework. The compromise was revealed through unusual, rapid publication of tags across multiple repositories, suggesting a broader breach of the Laravel Lang organization's release process. The malicious code, rooted in a file named src/helpers.php, executes automatically upon any PHP request due to its registration in composer.json under autoload.files, allowing it to act as a complex credential-harvesting framework targeting various sensitive data across cloud services, CI/CD pipelines, password managers, and more. The payload dynamically builds its Command and Control (C2) hostname to evade detection, retrieves additional malicious payloads, and executes them, while Aikido Security and Socket have publicly disclosed this breach to alert the Laravel and PHP communities. Affected teams are advised to treat systems as potentially compromised, rotate exposed credentials, and rebuild affected environments from known-good images while preserving logs and artifacts for further analysis.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 14 | 2,152 | 360 | 101 | +18% |
| Kubernetes | 6 | 1,965 | 371 | 106 | -15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.