Laravel Lang package compromise
Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.
Also tracked as Laravel Lang compromise
- First observed
- May 22, 2026
- Last observed
- May 23, 2026
- Last reviewed
- Sep 3, 2026
- Tracking ended
- Sep 8, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
The reviewed HOL Guard v3.0.18 release and tagged support matrix still label Packagist/Composer as Beta support, establishing partial coverage for eligible observed package actions rather than universal Composer runtime mediation. The v3.0.18 tag pyproject declares project version 3.0.1, so it is retained only as evidence of a metadata inconsistency and is not used as release-version proof.
- Composer support is Beta and partial. Lockfile review, registry advisories, secret rotation, and endpoint incident response remain necessary because Guard cannot retroactively remediate code that already executed through Composer autoload.
- The v3.0.18 tag pyproject declares project version 3.0.1; release-version provenance for this review therefore comes from the official v3.0.18 release record and matching release assets, not that pyproject version field.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
partial
The reviewed HOL Guard v3.0.18 support matrix labels Packagist/Composer Beta, so eligible Composer package actions can receive Guard supply-chain review. The reported malicious code executes through Composer autoload during application runtime; Guard does not claim universal mediation of that runtime path or retroactive remediation after execution.
- Recipe available
Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- First observed
Laravel Lang package compromise was first observed in the reviewed source material.
- Disclosure
The reviewed source published or updated its defensive analysis and remediation guidance.
- Correction
Coverage corrected from not_covered to partial after stable HOL Guard 2.0.1112 was reverified to label Packagist/Composer Beta; runtime/autoload execution remains outside a universal protection claim.
- Correction
Coverage evidence corrected to current stable HOL Guard 2.2.5 after PyPI release metadata showed 2.0.1112 was no longer the stable release; v2.2.5 still labels Packagist/Composer Beta, so the partial relationship is unchanged.
- Correction
Coverage evidence refreshed after the previously current 2.2.5 reference became obsolete; the reviewed HOL Guard v2.2.122 stable-line support matrix still labels Packagist/Composer Beta, so the partial relationship remains unchanged.
- Correction
Coverage evidence refreshed after HOL Guard v3.0.0 became the reviewed stable release; its support matrix still labels Packagist/Composer Beta, so the partial relationship and runtime/autoload limitation remain unchanged.
- Correction
Coverage evidence refreshed to the official v3.0.18 release. Composer remains Beta and Laravel remains partial coverage; the tagged pyproject version mismatch is recorded as inconsistent provenance rather than used as release-version evidence.
Publication clock: 1883.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
laravel-lang affected packagesComposerpackage
Sources
Every claim on this record is traceable to the sources below.
- Socket: Laravel Lang compromiseother primary · observed September 3, 2026
- HOL Guard 2.0.1112: Composer support matrixmaintainer advisory · observed September 3, 2026
- PyPI: HOL Guard stable release metadata at 2026-08-21other primary · observed September 3, 2026
- HOL Guard v2.2.5: Composer support matrixmaintainer advisory · observed September 3, 2026
- HOL Guard v2.2.122: stable-line project metadatamaintainer advisory · observed September 3, 2026
- HOL Guard v2.2.122: Composer support matrixmaintainer advisory · observed September 3, 2026
- HOL Guard v3.0.0: stable project metadatamaintainer advisory · observed September 3, 2026
- HOL Guard v3.0.0: Composer support matrixmaintainer advisory · observed September 3, 2026
- HOL Guard v3.0.18: official releasemaintainer advisory · observed September 3, 2026
- HOL Guard v3.0.18 tag: inconsistent project metadatamaintainer advisory · observed September 3, 2026
- HOL Guard v3.0.18: Composer support matrixmaintainer advisory · observed September 3, 2026
Record HGTC-2026-LARAVELANG