Theme:
Light Dark Auto
GeneralTop StoriesPoliticsBusinessEconomyTechnologyInternationalEnvironmentScienceSportsHealthEducationEntertainmentLifestyleCultureCrime & LawTravel & TourismFood & RecipesFact CheckReligion
TECHNOLOGY
Negative Sentiment

Des Paquets Laravel-Lang Empoisonnés par des Logiciels Malveillants

Read, Watch or Listen

Des Paquets Laravel-Lang Empoisonnés par des Logiciels Malveillants
Media Bias Meter
Sources: 2
Center 100%
Sources: 2

United States-based security researchers reported that four popular Laravel-Lang Composer packages were surreptitiously poisoned with malware after attackers manipulated Git tags to redirect users to malicious code, according to a SecurityWeek article published Monday. The affected PHP localization libraries are laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions, which are widely used by Laravel applications. Investigators from StepSecurity, Socket, and Aikido Security said the attack began on May 22, when attackers rewrote version tags across hundreds of historical releases to point to attacker-controlled commits in a fork, without altering the official GitHub repositories. By 00:00 UTC on May 23, all four packages had been poisoned, meaning both new installations and routine updates could have pulled in the compromised versions. United States security analysts said the malicious tags introduced a file named src/helpers.php that posed as a normal Laravel localization helper, but instead fingerprinted systems and contacted the command-and-control domain flipboxstudio[.]info to download and run a PHP-based credential stealer. Researchers reported that the malware targeted a wide range of secrets and configuration data on Windows, Linux, and macOS systems, including cloud keys for Amazon Web Services, Google Cloud Platform, and Microsoft Azure, as well as Docker and Kubernetes configurations, HashiCorp Vault tokens, SSH private keys, browser-stored credentials, password manager data, cryptocurrency wallets, communication tools, VPN configurations, CI/CD secrets, .env files, and other sensitive local application files. Security experts advised organizations and individual users to block the affected packages, treat any systems that installed the compromised versions as potentially breached, and rotate exposed credentials and tokens across cloud infrastructure, development environments, and source-control platforms.

Prepared by Jonathan Pierce and reviewed by editorial team.

Timeline of Events

  • 22 mai Les attaquants commencent à réécrire les tags Git
  • 22 mai Une fenêtre de quinze minutes permet une publication malveillante
  • Avant 00h00 UTC le 23 mai, les quatre packages Laravel-Lang sont empoisonnés
  • Fin mai 2024 Les chercheurs détectent une manipulation généralisée des tags
  • Fin mai 2024 Plus de 700 versions historiques retaguées de manière malveillante
  • Fin mai 2024 Aikido confirme qu'il n'y a pas de commits dans le dépôt officiel
  • Fin mai 2024 Les liens Socket compromettent le processus de publication
  • Lundi, SecurityWeek publie les conclusions de recherches coordonnées

Why This Matters to You

Vos applications Laravel pourraient être en danger. Les paquets empoisonnés pourraient voler vos données sensibles, des clés cloud aux clés privées SSH. Si vous avez installé ou mis à jour ces paquets depuis le 22 mai, votre système pourrait être compromis. Vérifiez vos applications Laravel dès maintenant.

The Bottom Line

Cette attaque par logiciel malveillant est un signal d'alarme. Elle montre comment les attaquants peuvent exploiter même des packages logiciels largement utilisés. Restez toujours vigilant avec les mises à jour et les installations. Si vous avez utilisé ces packages Laravel, changez vos identifiants et bloquez ceux qui sont affectés. Vaut la peine d'être transmis si vous connaissez quelqu'un qui utilise Laravel.

Media Bias
Articles Published:
1
Right Leaning:
0
Left Leaning:
0
Neutral:
1

Who Benefited

Non spécifié dans la source.

Who Impacted

Non spécifié dans la source.

Media Bias
Articles Published:
1
Right Leaning:
0
Left Leaning:
0
Neutral:
1
Distribution:
Left 0%, Center 100%, Right 0%
Who Benefited

Non spécifié dans la source.

Who Impacted

Non spécifié dans la source.

Coverage of Story:

From Left

No left-leaning sources found for this story.

From Center

Des Paquets Laravel-Lang Empoisonnés par des Logiciels Malveillants

JQJO
From Right

No right-leaning sources found for this story.

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET