// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / Laravel-Lang
Breach Record

Laravel-Lang

DISCLOSED 2026-05-25 · SUPPLY CHAIN

Four Laravel-Lang PHP localization packages were compromised in a supply chain attack, publishing 233 malicious versions on Packagist. The attacker exploited GitHub's tag system to point to a malicious fork, delivering a custom credential stealer targeting cloud keys, CI/CD tokens, and browser passwords. The attack window was May 22-23, 2026, and affected systems should be...

The record

What we know

Disclosed
2026-05-25
Attack vector
Supply Chain
Sources

Cited reporting

Similar vector · recent

Other supply chain breaches on file

This page is the permanent ColdRecon entry for the Laravel-Lang disclosure. It updates if new public reporting emerges. All tracked breaches →

Laravel-Lang just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →