{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-LARAVELANG","slug":"laravel-lang-package-compromise","title":"Laravel Lang package compromise","aliases":["Laravel Lang compromise"],"summary":"Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.","status":"published","severity":"high","confidence":"high","uncertainty":"HOL Guard does not currently publish Composer-specific interception support. This campaign is included to make that non-coverage explicit rather than imply universal package-manager protection.","firstObservedAt":"2026-05-22T00:00:00.000Z","lastObservedAt":"2026-05-23T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:socket-laravel-lang","label":"Socket: Laravel Lang compromise","url":"https://socket.dev/blog/laravel-lang-compromise","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:laravel-lang","artifactClass":"package","ecosystem":"Composer","name":"laravel-lang affected packages","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-05-22T00:00:00.000Z","eventType":"first_observed","summary":"Laravel Lang package compromise was first observed in the reviewed source material.","sourceIds":["source:socket-laravel-lang"]},{"id":"timeline:disclosure","occurredAt":"2026-05-23T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:socket-laravel-lang"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"not_covered","limitation":"The current Guard support manifest does not establish Composer package-install interception, so no protection claim is made for the affected Composer path."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."}],"limitations":["This record is a non-coverage example: Composer-specific enforcement is not currently verified in the public Guard support manifest."],"correctionHref":"/guard/security/campaigns/laravel-lang-package-compromise/corrections"}