2026-05-24HIGHPackagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
Packagist Laravel-Lang supply-chain wave
campaign · campaign:packagist-laravel-lang-supply-chain-2026
Packagist supply-chain wave: Laravel-Lang autoloader backdoor plus an eight-package cross-ecosystem postinstall strand.
Coverage
1
first 2026-05-24 → last 2026-05-24
Latest activity
2026-05-24
Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology, education · regions: europe
Sources cited
12
5 hosts
Defender insights
What each entry about Packagist Laravel-Lang supply-chain wave tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
ATT&CK techniques (12 across 5 tactics)
12 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessSupply Chain Compromise · Supply Chain Compromise: Compromise Software Supply Chain
- ExecutionCommand and Scripting Interpreter · Command and Scripting Interpreter: Unix Shell · User Execution · User Execution: Malicious File
- StealthMasquerading · Masquerading: Match Legitimate Resource Name or Location · Deobfuscate/Decode Files or Information
- Credential AccessUnsecured Credentials · Unsecured Credentials: Credentials In Files
- DiscoveryFile and Directory Discovery
Initial Access TA0001
T1195Supply Chain Compromise×1
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1204User Execution×1
An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
Stealth TA0005
T1036Masquerading×1
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
Discovery TA0007
T1083File and Directory Discovery×1
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗
Entries about Packagist Laravel-Lang supply-chain wave (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- attack.mitre.org7 (58%)
- socket.dev2 (17%)
- aikido.dev1 (8%)
- stepsecurity.io1 (8%)
- thehackernews.com1 (8%)
All cited sources (12)
- aikido.devAikido, 2026-05-23https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer
- attack.mitre.org`T1036.005`https://attack.mitre.org/techniques/T1036/005/
- attack.mitre.org`T1059.004`https://attack.mitre.org/techniques/T1059/004/
- attack.mitre.org`T1083`https://attack.mitre.org/techniques/T1083/
- attack.mitre.org`T1140`https://attack.mitre.org/techniques/T1140/
- attack.mitre.org`T1195.002`https://attack.mitre.org/techniques/T1195/002/
- attack.mitre.org`T1204.002`https://attack.mitre.org/techniques/T1204/002/
- attack.mitre.org`T1552.001`https://attack.mitre.org/techniques/T1552/001/
- socket.devSocket, Laravel-Lang, 2026-05-23https://socket.dev/blog/laravel-lang-compromise
- socket.devSocket, postinstall strand, 2026-05-22https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos
- stepsecurity.ioStepSecurity, 2026-05-22https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack
- thehackernews.comThe Hacker News, 2026-05-23https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html