{"type":"bundle","id":"bundle--92cc1471-4dca-5e03-86be-7ab3da5081ee","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--9a1cb1bd-de56-51e6-be11-66e3d788f8b9","created":"2026-08-09T11:30:00.000Z","modified":"2026-08-09T11:20:00.000Z","name":"Laravel Lang package compromise","description":"Socket documented a compromise of third-party Laravel Lang packages in which malicious code was introduced across many historical versions and could execute through Composer autoload behavior during normal application runtime.","aliases":["Laravel Lang compromise"],"first_seen":"2026-05-22T00:00:00.000Z","last_seen":"2026-05-23T00:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Socket: Laravel Lang compromise","url":"https://socket.dev/blog/laravel-lang-compromise"}]}]}