Reviewed threat campaign

Laravel Lang package compromise

Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.

Severity highConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

HOL Guard does not currently publish Composer-specific interception support. This campaign is included to make that non-coverage explicit rather than imply universal package-manager protection.

Limitations

Timeline

  1. · Laravel Lang package compromise was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 1883.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources