Nils Adermann
7.7K posts

Nils Adermann
@naderman
Co-Founder of @packagist / https://t.co/J7OZsciXbE and Co-Creator of #composerphp - he/him - @[email protected]


this supply chain attack is terrifying new video: youtu.be/j_MKR65tEW8?si…



🚨 Supply chain attack on the Laravel Lang organization: 700+ historical versions across multiple community-maintained Laravel Lang packages were compromised with an RCE backdoor, including: laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes Laravel-Lang/actions The payload targets cloud creds, CI/CD secrets, Kubernetes tokens, Vault, browser data, password managers, SSH keys, and more.




🚨 Security advisory: Composer 2.9.8 and 2.2.28 are out and fix a vulnerability leaking GitHub Actions new format GITHUB_TOKENs into job logs via error messages. Update now (composer self-update) or disable affected Actions workflows. #composerphp #phpc #php













