StepSecurity Logo
StepSecurity
    • Get Started

    • Overview

    • Threat Center

      • Workflow Runs

      • Baseline

      • Detections

      • Suppression Rules

      • Policy Store

      • Self Hosted Runners

      • Installation

    • Action Secrets

    • Apps & PATs

  1. compromised-packages
  2. Analyze Laravel-Lang/http-statuses Compromised Package

Jobs

  • download-package
  • install-compromised-package

install-compromised-package

Harden-runner policy:
audit
Start time:23 May 2026 00:35:59 GMTRunner name:-Duration:50sJob labels:ubuntu-latest
Show:
Show all steps
StepPIDProcessDestinationPortStatus
Setup PHPshivammathur/setup-php@v2
2077curlGitHubgithub.comAPI Calls1443Allowed23 May 2026 00:36:05
Setup PHPshivammathur/setup-php@v2
2077curlGitHubrelease-assets.githubusercontent.comAPI Calls1443Allowed23 May 2026 00:36:05
Install compromised laravel-lang/http-statuses v3.4.5
2367php8.2repo.packagist.orgAPI Calls1443Allowed23 May 2026 00:36:10
Install compromised laravel-lang/http-statuses v3.4.5
2367php8.2GitHubapi.github.comAPI Calls8443Allowed23 May 2026 00:36:12
Install compromised laravel-lang/http-statuses v3.4.5
2367php8.2packagist.orgAPI Calls1443Allowed23 May 2026 00:36:15
Autoload package to trigger runtime payload
2547/usr/bin/php8.2flipboxstudio.info443Attack Blocked23 May 2026 00:36:15