Threat reportSupply ChainTL-2026-0570
Laravel Lang Supply Chain Compromise — 700+ Backdoored Composer Versions Across 4 Packages Deliver RCE Backdoor and Cloud Credential Theft via flipboxstudio[.]info C2
Laravel Lang Supply Chain Compromise (TL-2026-0570), also tracked as Laravel Lang Backdoor, is a critical-severity supply-chain compromise scored CVSS 9.8, first published 2026-05-22. It has no confirmed attribution, affects laravel-lang (community) laravel-lang/lang (Composer), maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 23 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0570
- Threat ID
- TL-2026-0570
- Also known as
- Laravel Lang Backdoor, laravel-lang Composer Compromise, flipboxstudio C2 Campaign
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, saas, ecommerce, financial, media, education, government
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Laravel Lang Supply Chain Compromise
Malware and tooling: Custom PHP loader (flipboxstudio.info /payload + /exfil)
How Laravel Lang Supply Chain Compromise works
Socket Threat Research disclosed a large-scale supply chain compromise of the community-maintained laravel-lang Composer organization on 2026-05-23. Malicious code was injected into approximately 700+ historical Composer versions across four packages (laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, laravel-lang/actions). The backdoor is registered via composer.json autoload.files as src/helpers.php and executes on every PHP request, dynamically reconstructs the C2 hostname flipboxstudio[.]info from PHP chr() character codes, fetches a remote PHP payload, writes it to a hidden directory under sys_get_temp_dir(), executes it via PHP exec() on Unix or cscript on Windows (DebugChromium.exe artifact), and probes the cloud Instance Metadata Service at 169.254.169.254 to steal IAM credentials. Compromise vector is suspected to be organization-level credential theft or release-infrastructure abuse.
On 2026-05-23, Socket Threat Research published an analysis revealing that the community-maintained laravel-lang Composer organization was compromised, with malicious code injected into approximately 700+ historical version tags across four widely-used Laravel localization and helper packages: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. The backdoor affects version lines 12.x, 13.x, 14.x and 15.x with confirmed compromised builds including laravel-lang/lang@14.3.7.
Exploit Chain Analysis — The malicious payload is delivered by tampering with each package''s composer.json autoload.files directive, registering src/helpers.php as a globally autoloaded PHP file. Because composer.json autoload.files is included on every PHP request bootstrapping the affected vendor/ tree, the backdoor executes silently inside any Laravel application that has installed the compromised version, with no special endpoint or user action required. The src/helpers.php stub does not contain the C2 hostname in plaintext; instead, it reconstructs the string ''flipboxstudio.info'' character-by-character at runtime using a sequence of PHP chr() ASCII codes, evading naive grep- and YARA-based detection of the literal domain inside source files and vendor/ tarballs.
Once the C2 hostname is materialised, the backdoor issues an outbound HTTPS GET to https://flipboxstudio[.]info/payload to fetch a second-stage PHP loader. The loader is written to a hidden subdirectory beneath sys_get_temp_dir() — specifically <sys_get_temp_dir()>/.laravel_locale/ — masquerading as a benign Laravel locale cache directory. Execution then forks per platform: on Unix-like hosts the dropped PHP file is invoked via PHP exec() against the local PHP binary, while on Windows hosts the loader is invoked via cscript and is observed dropping a renamed Chromium-style binary named DebugChromium.exe to blend with legitimate browser update artifacts.
Post-Exploitation and Credential Theft — After the second-stage loader executes, the backdoor enumerates the cloud Instance Metadata Service (IMDS) at 169.254.169.254 to harvest temporary IAM role credentials from AWS, GCP and Azure metadata endpoints. Stolen credentials, environment variables (.env contents, CI/CD secrets), and host fingerprint data are then exfiltrated by HTTPS POST to https://flipboxstudio[.]info/exfil. Because Laravel applications routinely run as long-lived workers and frequently hold AWS_*/GCP_*/AZURE_* credentials in environment variables alongside DB_PASSWORD, APP_KEY and third-party API tokens, a single compromised laravel-lang install yields a high-value secret bundle.
C2 Infrastructure — The C2 domain flipboxstudio[.]info impersonates ''flipbox studio'' — a name that closely resembles a legitimate Indonesian Laravel agency, providing thin plausible-deniability if surfaced in firewall logs. The .info TLD, generic-looking subdomain layout, and the use of /payload and /exfil endpoint suffixes on the same host suggest a single staged C2 server rather than a redirector chain.
Distribution Mechanism — All four packages are distributed via Packagist (the canonical Composer registry) and tagged from a single GitHub organization. The fact that ~700 historical version tags across four packages were simultaneously poisoned indicates the attacker had write access to either the GitHub organization (push/tag rights) or the Packagist publishing pipeline, and used that access to rewrite history rather than publishing one-off malicious versions. This is consistent with a compromise of organization-level credentials (a maintainer Personal Access Token, GitHub Actions OIDC token, or Packagist API key) or release-infrastructure abuse such as a poisoned GitHub Actions workflow that re-tags releases.
Impact — Any Laravel application that ran ''composer install'' or ''composer update'' resolving an affected version is compromised. Because Composer''s composer.lock pins to git refs and most CI/CD pipelines run ''composer install'' on every build, the blast radius extends to every CI runner, container image and production replica that has rebuilt against an affected version. Stolen IAM credentials enable lateral movement across cloud environments (S3 bucket read/write, EC2/ECS launch, Lambda invoke, KMS decrypt), enabling secondary supply chain attacks, data exfiltration and ransomware staging.
Attribution and Motivation — Socket does not attribute the compromise to a named actor. The combination of broad historical version poisoning (mass-impact targeting rather than victim-specific), cloud metadata theft (financially monetisable credential resale or follow-on intrusion), and a single C2 endpoint with weak operational hygiene is consistent with financially-motivated criminal supply chain actors (similar in pattern to the npm ua-parser-js, ctx/phppass and PyTorch torchtriton compromises) rather than nation-state activity.
MITRE ATT&CK techniques used in TL-2026-0570
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution
Discovery
T1082 System Information Discovery; T1580 Cloud Infrastructure Discovery
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Impact
Credential Access
stealth
Resource Development
Affected products and versions in Laravel Lang Supply Chain Compromise
- laravel-lang (community) — laravel-lang/lang (Composer)
Vulnerable versions: 12.x; 13.x; 14.x; 15.x — ~700 historical tags including 14.3.7
Fixed in: Pending vendor-confirmed safe rebuild; see Socket advisory - laravel-lang (community) — laravel-lang/http-statuses (Composer)
Vulnerable versions: 12.x; 13.x; 14.x; 15.x
Fixed in: Pending vendor-confirmed safe rebuild - laravel-lang (community) — laravel-lang/attributes (Composer)
Vulnerable versions: 12.x; 13.x; 14.x; 15.x
Fixed in: Pending vendor-confirmed safe rebuild - laravel-lang (community) — laravel-lang/actions (Composer)
Vulnerable versions: 12.x; 13.x; 14.x; 15.x
Fixed in: Pending vendor-confirmed safe rebuild
Remediation for Laravel Lang Supply Chain Compromise
Patches
- No upstream patch — abandoned/compromised organization. Pin to last vendor-confirmed safe version per Socket advisory and consider forking
- Coordinate with Packagist (security@packagist.org) to remove poisoned tags
- Rebuild all dependent applications with cleaned composer.lock and rotated dependencies
Immediate actions
- Block flipboxstudio[.]info and all subdomains at DNS sinkhole / egress proxy / web filter
- Block egress to 169.254.169.254 from PHP/Laravel containers that do not require IMDS
- Audit composer.lock for laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, laravel-lang/actions at any version in lines 12.x-15.x and pin to vendor-confirmed safe versions
- Run a filesystem sweep for src/helpers.php inside vendor/laravel-lang/*/ that registers global autoload files containing chr()-encoded strings
- Hunt for <sys_get_temp_dir()>/.laravel_locale/ on all PHP hosts and quarantine contents
- Hunt for DebugChromium.exe in %TEMP%, %APPDATA%, and ProgramData on Windows hosts running PHP
- Rotate all cloud IAM keys, .env secrets, DB credentials, APP_KEY and third-party API tokens used by any application that installed an affected version since 2026-01-01
- Pull build cache (CI runner /tmp, container layers, ephemeral storage) and reset to ensure backdoor is not persisted in cached vendor/ trees
Workarounds
- Temporarily remove laravel-lang/* from composer.json and replace with framework-native trans()/__() resources or an alternative localization library
- Pre-install vendor/ from a known-clean Composer cache and freeze composer install in CI
Longer-term hardening
- Mandate composer.lock pinning and verify package integrity via composer-require-checker and roave/security-advisories
- Deploy a Composer dependency firewall (e.g. Socket for Composer, Snyk, JFrog Xray) that blocks newly-introduced or recently-modified versions until a quarantine window passes
- Restrict outbound network access from PHP CLI and php-fpm to a deny-by-default allowlist, especially blocking 169.254.169.254 in containers that do not need IMDSv2
- Migrate to IMDSv2 with hop-limit=1 to defeat SSRF-style metadata theft from compromised application processes
- Implement EDR rules detecting PHP processes spawning cscript.exe or exec()-ing files under sys_get_temp_dir()
- Audit GitHub organization permissions, enforce branch protection and signed tags, rotate maintainer PATs and adopt short-lived OIDC tokens for releases
Weaknesses (CWE) in Laravel Lang Supply Chain Compromise
Timeline of Laravel Lang Supply Chain Compromise
- Estimated earliest possible window for retroactive version-tag tampering across the laravel-lang organization, based on ~700 historical version tags affected across four packages
- Threadlinqs Intelligence @Pentester engaged to produce safe attack simulations for purple-team validation
- Threadlinqs Intelligence ingests threat; @Detector engaged to build SPL/KQL/Sigma detections for vendor-tree tampering, IMDS access from PHP, and flipboxstudio[.]info egress
- Composer/Packagist community advisories and downstream Laravel security channels begin coordinating affected-version lists and removal of poisoned tags
- Threat meets CISA KEV criteria (active exploitation, widely-used software, RCE) and is flagged as KEV candidate pending CISA review
- C2 domain flipboxstudio[.]info, payload endpoint /payload, exfiltration endpoint /exfil, staging directory <sys_get_temp_dir()>/.laravel_locale/ and Windows artifact DebugChromium.exe published as IOCs
- Socket Threat Research publishes ''Laravel Lang Compromised with RCE Backdoor Across 700+ Versions'' identifying the backdoor in laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, laravel-lang/actions
- As of 2026-05-29, the poisoned laravel-lang Composer tags were removed/unlisted by Packagist within hours of the May 22-23 disclosure, containing the distribution vector. But 5,561+ downstream repos and CI caches may still carry the backdoor, the flipboxstudio[.]info C2 has no confirmed takedown, stolen creds need rotation, and the actor is unidentified.
Sources cited for Laravel Lang Supply Chain Compromise
- Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
- Packagist — laravel-lang/lang
- GitHub — Laravel-Lang organization
- Composer Autoload Reference (autoload.files)
- AWS — IMDSv2 mitigations for SSRF and credential theft
- MITRE ATT&CK — Compromise Software Supply Chain (T1195.002)
- MITRE ATT&CK — Cloud Instance Metadata API (T1552.005)
Detection coverage for TL-2026-0570
As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0570 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.