# Laravel Lang Supply Chain Compromise — 700+ Backdoored Composer Versions Across 4 Packages Deliver RCE Backdoor and Cloud Credential Theft via flipboxstudio[.]info C2

> Socket Threat Research disclosed a large-scale supply chain compromise of the community-maintained laravel-lang Composer organization on 2026-05-23. Malicious code was injected into approximately 700+ historical Composer versions across four packages (laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, laravel-lang/actions). The backdoor is registered via composer.json autoload.files as src/helpers.php and executes on every PHP request, dynamically reconstructs the C2 hostname flipboxstudio[.]info from PHP chr() character codes, fetches a remote PHP payload, writes it to a hidden directory under sys_get_temp_dir(), executes it via PHP exec() on Unix or cscript on Windows (DebugChromium.exe artifact), and probes the cloud Instance Metadata Service at 169.254.169.254 to steal IAM credentials. Compromise vector is suspected to be organization-level credential theft or release-infrastructure abuse.

- **Published:** 2026-05-22T12:00:00Z
- **Last reviewed:** 2026-05-22T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0570
- **ID:** TL-2026-0570
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-05-23, Socket Threat Research published an analysis revealing that the community-maintained laravel-lang Composer organization was compromised, with malicious code injected into approximately 700+ historical version tags across four widely-used Laravel localization and helper packages: laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions. The backdoor affects version lines 12.x, 13.x, 14.x and 15.x with confirmed compromised builds including laravel-lang/lang@14.3.7.

Exploit Chain Analysis — The malicious payload is delivered by tampering with each package''s composer.json autoload.files directive, registering src/helpers.php as a globally autoloaded PHP file. Because composer.json autoload.files is included on every PHP request bootstrapping the affected vendor/ tree, the backdoor executes silently inside any Laravel application that has installed the compromised version, with no special endpoint or user action required. The src/helpers.php stub does not contain the C2 hostname in plaintext; instead, it reconstructs the string ''flipboxstudio.info'' character-by-character at runtime using a sequence of PHP chr() ASCII codes, evading naive grep- and YARA-based detection of the literal domain inside source files and vendor/ tarballs.

Once the C2 hostname is materialised, the backdoor issues an outbound HTTPS GET to https://flipboxstudio[.]info/payload to fetch a second-stage PHP loader. The loader is written to a hidden subdirectory beneath sys_get_temp_dir() — specifically <sys_get_temp_dir()>/.laravel_locale/ — masquerading as a benign Laravel locale cache directory. Execution then forks per platform: on Unix-like hosts the dropped PHP file is invoked via PHP exec() against the local PHP binary, while on Windows hosts the loader is invoked via cscript and is observed dropping a renamed Chromium-style binary named DebugChromium.exe to blend with legitimate browser update artifacts.

Post-Exploitation and Credential Theft — After the second-stage loader executes, the backdoor enumerates the cloud Instance Metadata Service (IMDS) at 169.254.169.254 to harvest temporary IAM role credentials from AWS, GCP and Azure metadata endpoints. Stolen credentials, environment variables (.env contents, CI/CD secrets), and host fingerprint data are then exfiltrated by HTTPS POST to https://flipboxstudio[.]info/exfil. Because Laravel applications routinely run as long-lived workers and frequently hold AWS_*/GCP_*/AZURE_* credentials in environment variables alongside DB_PASSWORD, APP_KEY and third-party API tokens, a single compromised laravel-lang install yields a high-value secret bundle.

C2 Infrastructure — The C2 domain flipboxstudio[.]info impersonates ''flipbox studio'' — a name that closely resembles a legitimate Indonesian Laravel agency, providing thin plausible-deniability if surfaced in firewall logs. The .info TLD, generic-looking subdomain layout, and the use of /payload and /exfil endpoint suffixes on the same host suggest a single staged C2 server rather than a redirector chain.

Distribution Mechanism — All four packages are distributed via Packagist (the canonical Composer registry) and tagged from a single GitHub organization. The fact that ~700 historical version tags across four packages were simultaneously poisoned indicates the attacker had write access to either the GitHub organization (push/tag rights) or the Packagist publishing pipeline, and used that access to rewrite history rather than publishing one-off malicious versions. This is consistent with a compromise of organization-level credentials (a maintainer Personal Access Token, GitHub Actions OIDC token, or Packagist API key) or release-infrastructure abuse such as a poisoned GitHub Actions workflow that re-tags releases.

Impact — Any Laravel application that ran ''composer install'' or ''composer update'' resolving an affected version is compromised. Because Composer''s composer.lock pins to git refs and most CI/CD pipelines run ''composer install'' on every build, the blast radius extends to every CI runner, container image and production replica that has rebuilt against an affected version. Stolen IAM credentials enable lateral movement across cloud environments (S3 bucket read/write, EC2/ECS launch, Lambda invoke, KMS decrypt), enabling secondary supply chain attacks, data exfiltration and ransomware staging.

Attribution and Motivation — Socket does not attribute the compromise to a named actor. The combination of broad historical version poisoning (mass-impact targeting rather than victim-specific), cloud metadata theft (financially monetisable credential resale or follow-on intrusion), and a single C2 endpoint with weak operational hygiene is consistent with financially-motivated criminal supply chain actors (similar in pattern to the npm ua-parser-js, ctx/phppass and PyTorch torchtriton compromises) rather than nation-state activity.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1574 Hijack Execution Flow
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1070 Indicator Removal
- T1552 Unsecured Credentials
- T1580 Cloud Infrastructure Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1568 Dynamic Resolution
- T1041 Exfiltration Over C2 Channel
- T1496 Resource Hijacking

## Sources

- [Laravel Lang Compromised with RCE Backdoor Across 700+ Versions](https://socket.dev/blog/laravel-lang-compromise)
- [Packagist — laravel-lang/lang](https://packagist.org/packages/laravel-lang/lang)
- [GitHub — Laravel-Lang organization](https://github.com/Laravel-Lang)
- [Composer Autoload Reference (autoload.files)](https://getcomposer.org/doc/04-schema.md#files)
- [AWS — IMDSv2 mitigations for SSRF and credential theft](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-instance-metadata-service.html)
- [MITRE ATT&CK — Compromise Software Supply Chain (T1195.002)](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK — Cloud Instance Metadata API (T1552.005)](https://attack.mitre.org/techniques/T1552/005/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0570
