Tag
#packagist
3 stories taggedpackagist.

Threat Intelligence
Laravel-Lang Packages Hijacked to Push a Cross-Platform Credential Stealer
Four popular Laravel-Lang packages were tagged with malicious releases that drop a credential-harvesting framework on Windows, macOS, and Linux.
3 min read

Threat Intelligence
Eight Packagist Projects Hijacked to Pull Linux Payload From GitHub Releases
The injected code lived in package.json, not composer.json, and targeted JavaScript-shipping Composer projects.
2 min read

Threat Intelligence
Laravel Lang Composer packages backdoored via GitHub tag rewrite, dropping infostealer on developer machines
Attackers reused legitimate version tags on the laravel-lang GitHub repository to push malicious Composer payloads to downstream installs, harvesting credentials from build environments.
2 min read