Attackers rewrote git tags in Laravel-Lang PHP packages to inject a credential stealing payload that executes silently on application startup.