Famous Chollima Targets PHP Developers Through Compromised Packagist Package
2026-05-31 • Socket •
https://socket.dev/blog/famous-chollima-targets-php-developers-through-compromised-packagist-package
A malicious JavaScript loader was appended to `tailwind.js` in the Packagist dev version `dev-drewroberts/feature/test-case` of the legitimate PHP package `roberts/leads`. Socket assesses the activity as likely tied to Famous Chollima and consistent with a Contagious Interview-style developer lure, because the compromise was limited to a dev/test branch that a target could be instructed to install during a fake coding task. The loader uses TRON, Aptos, and BNB Smart Chain infrastructure as a dead-drop mechanism, decrypts remote payload material with hardcoded XOR keys, executes it with `eval()`, and can spawn a hidden detached Node.js process. The visible loader does not directly exfiltrate data, but the fetched payload could access environment variables, local files, Git credentials, package tokens, and CI/cloud secrets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0x3f0e5781d0855fb460661ac632573… | 2026-05-31 | 2026-05-31 |
| WALLET | 0xbe037400670fbf1c32364f7629759… | 2026-05-31 | 2026-05-31 |
| WALLET | TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… | 2026-05-31 | 2026-05-31 |
| WALLET | TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… | 2026-05-31 | 2026-05-31 |
| HASH | 96afdba882046385242cbed46871e41… | 2026-05-31 | 2026-05-31 |
| HASH | 522b28a2f78771715497ba53729d4ab… | 2026-05-31 | 2026-05-31 |
| HASH | 6c5c3c7655ce76399af11126b7e9a90… | 2026-05-31 | 2026-05-31 |
| DOMAIN | api.trongrid.io | 2025-10-27 | 2026-05-31 |
| DOMAIN | fullnode.mainnet.aptoslabs.com | 2025-10-27 | 2026-05-31 |
| URL | https://api.trongrid.io/v1/acco… | 2025-10-27 | 2025-11-13 |