Laravel-Lang Supply Chain Attack 2026: How 700+ Composer Tags Got Hijacked and How to Defend Your Stack
On May 22, 2026, attackers rewrote every git tag across four laravel-lang Composer packages in a 15-minute window, planting a 5,900-line credential stealer in any project that ran composer install from a cold cache. Here is what happened, how to verify your install, and the CI controls that would have stopped it.