{
  "title": "Laravel-Lang Composer Tag Rewrite RCE Compromise",
  "summary": "Four Laravel-Lang repositories were compromised through rewritten Composer tags that loaded a PHP backdoor through Composer autoload. Maintainers restored the tags on May 23, but installs from the exposure window require credential rotation and commit-level verification.",
  "date": "2026-05-24",
  "severity": "critical",
  "tags": [
    "supply-chain",
    "packagist",
    "composer",
    "laravel",
    "credential-theft"
  ],
  "sources_count": 5,
  "indicators": {
    "slug": "laravel-lang-composer-tag-compromise",
    "since": "2026-05-22T22:32:00Z",
    "until": "unknown",
    "ecosystem": "",
    "cves": [],
    "cwes": [],
    "advisoryIds": [],
    "products": [],
    "packages": [],
    "versions": [],
    "affectedVersions": [],
    "fixedVersions": [],
    "files": [],
    "paths": [],
    "services": [],
    "domains": [
      "helpers.php",
      "autoload.files",
      "flipboxstudio.info",
      "autoload.php"
    ],
    "urls": [
      "https://flipboxstudio.info/payload",
      "https://flipboxstudio.info/exfil"
    ],
    "ips": [],
    "hashes": [
      "2f0ee073c6f29d66188a845592029c9b52528f04"
    ],
    "processPatterns": [],
    "networkPatterns": [],
    "telemetrySelectors": []
  }
}