

Di
2.5K posts

@DianaWebdev
I love PHP. Did someone say coffee? Fullstack Witch @beyondcode, working on Tinkerwell, Laravel Herd and more magic • she/her @dianawebdev.bsky.social



🚨 Ongoing supply chain attack on Composer packages! We just found multiple laravel-lang/* packages compromised on Packagist (lang, http-statuses, attributes). Payload runs at autoload time. At least 50 package versions were compromised. If you installed a compromised version, the malware already executed. Pin to a clean COMMIT (not version) and rotate secrets immediately. If your lockfile already had an older commit from before today, you are safe. But you should not update at the moment.

















