Famous Chollima Targets PHP Developers Through Compromised Packagist Package

2026-05-31 Socket

https://socket.dev/blog/famous-chollima-targets-php-developers-through-compromised-packagist-package

Thumbnail for Famous Chollima Targets PHP Developers Through Compromised Packagist Package

A malicious JavaScript loader was appended to `tailwind.js` in the Packagist dev version `dev-drewroberts/feature/test-case` of the legitimate PHP package `roberts/leads`. Socket assesses the activity as likely tied to Famous Chollima and consistent with a Contagious Interview-style developer lure, because the compromise was limited to a dev/test branch that a target could be instructed to install during a fake coding task. The loader uses TRON, Aptos, and BNB Smart Chain infrastructure as a dead-drop mechanism, decrypts remote payload material with hardcoded XOR keys, executes it with `eval()`, and can spawn a hidden detached Node.js process. The visible loader does not directly exfiltrate data, but the fetched payload could access environment variables, local files, Git credentials, package tokens, and CI/cloud secrets.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0x3f0e5781d0855fb460661ac632573… 2026-05-31 2026-05-31
WALLET 0xbe037400670fbf1c32364f7629759… 2026-05-31 2026-05-31
WALLET TXfxHUet9pJVU1BgVkBAbrES4YUc1nG… 2026-05-31 2026-05-31
WALLET TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7… 2026-05-31 2026-05-31
HASH 96afdba882046385242cbed46871e41… 2026-05-31 2026-05-31
HASH 522b28a2f78771715497ba53729d4ab… 2026-05-31 2026-05-31
HASH 6c5c3c7655ce76399af11126b7e9a90… 2026-05-31 2026-05-31
DOMAIN api.trongrid.io 2025-10-27 2026-05-31
DOMAIN fullnode.mainnet.aptoslabs.com 2025-10-27 2026-05-31
URL https://api.trongrid.io/v1/acco… 2025-10-27 2025-11-13

Related Actors

Related Reports

2025-11-26 • 52% Match
#NPM #ContagiousInterview #OtterCookie #T1082 #T1119 #T1005 #T1587.001 #T1041 #T1113 #T1608.001 #T1195.002 #T1115 #T1083 #T1497 #T1056.001 #T1059.007 #T1036 #T1204.002 #T1555.003 #T1583.006 #T1547.001 #T1539 #T1583.001 #T1656 #T1105 #T1204.005 #T1571 #T1657 #T1587 #T1585 #T1555.001 #T1546.016 #T1217
Shares tags: ContagiousInterview, T1195.002, T1059.007 • Same author: Socket
« Back