Famous Chollima Targets PHP Developers Through Compromised Packagist Package
ID: 9020ee3d-922f-5f70-a200-1fbbe6dd55a1
STIX ID: report--9020ee3d-922f-5f70-a200-1fbbe6dd55a1
Feed Name: Socket Blog
A Packagist development version of the PHP package roberts/leads contained obfuscated JavaScript appended to tailwind.js that functions as a blockchain-based loader: it retrieves encrypted payloads via TRON/Aptos/BSC transaction data, XOR-decrypts them, executes code with eval, and can spawn a hidden Node.js child process; IoCs and behavior align with prior DPRK-linked Famous Chollima supply-chain campaigns and suggest a targeted developer-lure (e.g., fake interview) rather than broad distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
