Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Between May 22-23, 2026, attackers compromised the Laravel-Lang GitHub organization and injected malicious code into 700+ version tags across four widely used PHP packages. Any PHP application that pulled these packages via Composer will auto-execute the payload on startup, exposing cloud credentials (AWS, Azure, GCP), CI/CD pipeline tokens, cryptocurrency wallets, browser-stored passwords, and SSH keys to an attacker-controlled server. The breach affects Laravel, Symfony, and PHPUnit ecosystems, meaning the scope of compromise extends across a significant portion of the PHP software supply chain.

Author

Tech Jacks Solutions