Famous Chollima-Linked Campaign Targets PHP Developers Through Malicious Packagist Branch

· Original article ↗

Summary

Socket researchers found an obfuscated JavaScript loader in an installable development branch of a PHP package. It retrieves encrypted payloads through blockchain infrastructure; Packagist removed the version after notification.

Key points

  • Malicious code was appended to tailwind.js in the installable dev-drewroberts/feature/test-case version of roberts/leads; the reviewed stable release did not show the same indicators.
  • The obfuscated Node.js loader retrieves encrypted payload material using TRON, Aptos, and BNB Smart Chain infrastructure, decrypts it with XOR keys, and executes it.
  • The loader can launch a detached, hidden Node.js process; its visible code does not itself exfiltrate files or credentials, but the remote payload can access local files, environment variables, and available credentials.
  • Researchers assess the activity as likely involving a developer or repository compromise or a poisoned-branch workflow, potentially consistent with a fake job or developer-task lure.
  • The campaign is associated by the researchers with North Korean APT activity and Famous Chollima; prior reporting on overlapping infrastructure linked it to several malware families.
  • Packagist removed the malicious version after notification. Developers and security teams are advised to inspect unfamiliar build files and dev branches, monitor suspicious Node.js activity, and limit or rotate exposed CI credentials.

Article Details

Attack Vectors
  • Malicious JavaScript was appended after legitimate configuration code in an installable development branch of an otherwise legitimate PHP package. Researchers assessed a likely developer or repository compromise, or poisoned-branch workflow; the stable release line did not show the same indicators in their review.
  • A large whitespace gap concealed the appended payload during routine code review. Obfuscated global aliases reconstructed runtime internals before executing decoded staging code.
  • The loader retrieved payload pointers from blockchain transactions, obtained encrypted JavaScript through public RPC infrastructure, decrypted it using embedded XOR keys, and executed it in-process or through a hidden detached child process.
  • Researchers assessed that explicit development-version installation or branch checkout could support a fake interview or developer-task lure. They did not identify public instructions directing victims to this exact version or evidence of broad organic exposure.
  • The visible loader did not directly exfiltrate data. Additional targeting or exfiltration behavior would reside in remote payloads, whose execution could expose local files, process secrets, credentials, and source code.
Defensive Notes
  • The package registry reviewed the report and removed the malicious development version. Researchers also notified the maintainer and submitted the affected repository file for security review.
  • Treat unfamiliar interview tasks, project setup commands, and development-branch builds as code execution events; inspect dependency manifests, build configurations, workflow files, and scripts before running them.
  • Monitor build-time JavaScript runtime processes contacting blockchain or RPC services, particularly when followed by inline execution, detached child processes, or hidden windows.
  • Limit CI secret scope, avoid exposing long-lived credentials to branch builds, and rotate credentials after suspicious package execution.
  • Pin known-good package versions and review stability settings and explicit development dependency constraints.
  • Review branch protections, personal access tokens, OAuth applications, registry webhooks, deploy keys, and collaborator permissions. Preserve branch and commit evidence before deletion.
  • Scan local files and repository references for the reported loader markers, blockchain-service strings, transaction-query methods, and hidden-process options.

Indicators of compromise

TypeIndicatorContext
SHA256522b28a2f78771715497ba53729d4ab9a50e982322c391379f3bddf7c8cb363fSHA-256 of the archive associated with the malicious development version.
SHA25696afdba882046385242cbed46871e41147c8055c5d9eff7460847b2c01a77dc3SHA-256 of tailwind.js containing the malicious loader.
URLhxxps[:]//github[.]com/roberts/leads/blob/drewroberts/feature/test-case/tailwind[.]jsSpecific file on the affected development branch containing the appended malicious JavaScript loader.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Countries

Related Articles