Reviewed threat campaign
Laravel Lang package compromise
Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.
Uncertainty
HOL Guard does not currently publish Composer-specific interception support. This campaign is included to make that non-coverage explicit rather than imply universal package-manager protection.
Limitations
- This record is a non-coverage example: Composer-specific enforcement is not currently verified in the public Guard support manifest.
Timeline
- · Laravel Lang package compromise was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 1883.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- not covered: coverage:stable:codex — The current Guard support manifest does not establish Composer package-install interception, so no protection claim is made for the affected Composer path.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Sources
- Socket: Laravel Lang compromise · observed 2026-08-09