high severityConfidence highHistorical record

Laravel Lang package compromise

Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.

Also tracked as Laravel Lang compromise

First observed
May 22, 2026
Last observed
May 23, 2026
Last reviewed
Sep 3, 2026
Tracking ended
Sep 8, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

The reviewed HOL Guard v3.0.18 release and tagged support matrix still label Packagist/Composer as Beta support, establishing partial coverage for eligible observed package actions rather than universal Composer runtime mediation. The v3.0.18 tag pyproject declares project version 3.0.1, so it is retained only as evidence of a metadata inconsistency and is not used as release-version proof.

  • Composer support is Beta and partial. Lockfile review, registry advisories, secret rotation, and endpoint incident response remain necessary because Guard cannot retroactively remediate code that already executed through Composer autoload.
  • The v3.0.18 tag pyproject declares project version 3.0.1; release-version provenance for this review therefore comes from the official v3.0.18 release record and matching release assets, not that pyproject version field.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • partial

    The reviewed HOL Guard v3.0.18 support matrix labels Packagist/Composer Beta, so eligible Composer package actions can receive Guard supply-chain review. The reported malicious code executes through Composer autoload during application runtime; Guard does not claim universal mediation of that runtime path or retroactive remediation after execution.

  • Recipe available

    Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.

    Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. First observed

    Laravel Lang package compromise was first observed in the reviewed source material.

  2. Disclosure

    The reviewed source published or updated its defensive analysis and remediation guidance.

  3. Correction

    Coverage corrected from not_covered to partial after stable HOL Guard 2.0.1112 was reverified to label Packagist/Composer Beta; runtime/autoload execution remains outside a universal protection claim.

  4. Correction

    Coverage evidence corrected to current stable HOL Guard 2.2.5 after PyPI release metadata showed 2.0.1112 was no longer the stable release; v2.2.5 still labels Packagist/Composer Beta, so the partial relationship is unchanged.

  5. Correction

    Coverage evidence refreshed after the previously current 2.2.5 reference became obsolete; the reviewed HOL Guard v2.2.122 stable-line support matrix still labels Packagist/Composer Beta, so the partial relationship remains unchanged.

  6. Correction

    Coverage evidence refreshed after HOL Guard v3.0.0 became the reviewed stable release; its support matrix still labels Packagist/Composer Beta, so the partial relationship and runtime/autoload limitation remain unchanged.

  7. Correction

    Coverage evidence refreshed to the official v3.0.18 release. Composer remains Beta and Laravel remains partial coverage; the tagged pyproject version mismatch is recorded as inconsistent provenance rather than used as release-version evidence.

Publication clock: 1883.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • laravel-lang affected packagesComposerpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Research.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-LARAVELANG