logo

Famous Chollima Targets PHP Developers Through Compromised Packagist Package

ID: 9020ee3d-922f-5f70-a200-1fbbe6dd55a1

STIX ID: report--9020ee3d-922f-5f70-a200-1fbbe6dd55a1

Feed Name: Socket Blog

Threat Score
85/100

Date Published: 2026-05-31

Date Updated: 2026-06-11

Author: Kirill Boychenko

...
...

A Packagist development version of the PHP package roberts/leads contained obfuscated JavaScript appended to tailwind.js that functions as a blockchain-based loader: it retrieves encrypted payloads via TRON/Aptos/BSC transaction data, XOR-decrypts them, executes code with eval, and can spawn a hidden Node.js child process; IoCs and behavior align with prior DPRK-linked Famous Chollima supply-chain campaigns and suggest a targeted developer-lure (e.g., fake interview) rather than broad distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.