Famous Chollima-Linked Campaign Targets PHP Developers Through Malicious Packagist Branch

Summary
Socket researchers found an obfuscated JavaScript loader in an installable development branch of a PHP package. It retrieves encrypted payloads through blockchain infrastructure; Packagist removed the version after notification.
Key points
- Malicious code was appended to tailwind.js in the installable dev-drewroberts/feature/test-case version of roberts/leads; the reviewed stable release did not show the same indicators.
- The obfuscated Node.js loader retrieves encrypted payload material using TRON, Aptos, and BNB Smart Chain infrastructure, decrypts it with XOR keys, and executes it.
- The loader can launch a detached, hidden Node.js process; its visible code does not itself exfiltrate files or credentials, but the remote payload can access local files, environment variables, and available credentials.
- Researchers assess the activity as likely involving a developer or repository compromise or a poisoned-branch workflow, potentially consistent with a fake job or developer-task lure.
- The campaign is associated by the researchers with North Korean APT activity and Famous Chollima; prior reporting on overlapping infrastructure linked it to several malware families.
- Packagist removed the malicious version after notification. Developers and security teams are advised to inspect unfamiliar build files and dev branches, monitor suspicious Node.js activity, and limit or rotate exposed CI credentials.
Article Details
- Attack Vectors
- Malicious JavaScript was appended after legitimate configuration code in an installable development branch of an otherwise legitimate PHP package. Researchers assessed a likely developer or repository compromise, or poisoned-branch workflow; the stable release line did not show the same indicators in their review.
- A large whitespace gap concealed the appended payload during routine code review. Obfuscated global aliases reconstructed runtime internals before executing decoded staging code.
- The loader retrieved payload pointers from blockchain transactions, obtained encrypted JavaScript through public RPC infrastructure, decrypted it using embedded XOR keys, and executed it in-process or through a hidden detached child process.
- Researchers assessed that explicit development-version installation or branch checkout could support a fake interview or developer-task lure. They did not identify public instructions directing victims to this exact version or evidence of broad organic exposure.
- The visible loader did not directly exfiltrate data. Additional targeting or exfiltration behavior would reside in remote payloads, whose execution could expose local files, process secrets, credentials, and source code.
- Defensive Notes
- The package registry reviewed the report and removed the malicious development version. Researchers also notified the maintainer and submitted the affected repository file for security review.
- Treat unfamiliar interview tasks, project setup commands, and development-branch builds as code execution events; inspect dependency manifests, build configurations, workflow files, and scripts before running them.
- Monitor build-time JavaScript runtime processes contacting blockchain or RPC services, particularly when followed by inline execution, detached child processes, or hidden windows.
- Limit CI secret scope, avoid exposing long-lived credentials to branch builds, and rotate credentials after suspicious package execution.
- Pin known-good package versions and review stability settings and explicit development dependency constraints.
- Review branch protections, personal access tokens, OAuth applications, registry webhooks, deploy keys, and collaborator permissions. Preserve branch and commit evidence before deletion.
- Scan local files and repository references for the reported loader markers, blockchain-service strings, transaction-query methods, and hidden-process options.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA256 | 522b28a2f78771715497ba53729d4ab9a50e982322c391379f3bddf7c8cb363f | SHA-256 of the archive associated with the malicious development version. |
| SHA256 | 96afdba882046385242cbed46871e41147c8055c5d9eff7460847b2c01a77dc3 | SHA-256 of tailwind.js containing the malicious loader. |
| URL | hxxps[:]//github[.]com/roberts/leads/blob/drewroberts/feature/test-case/tailwind[.]js | Specific file on the affected development branch containing the appended malicious JavaScript loader. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationAppended JavaScript is obfuscated, reconstructs runtime aliases, and is concealed after a large whitespace gap in tailwind.js.T1059.007 · JavaScriptThe loader executes retrieved JavaScript with eval() and can run a second stage through node -e.T1102.001 · Dead Drop ResolverTRON transaction data supplies payload pointers, with Aptos transaction data used as a fallback resolver.T1105 · Ingress Tool TransferThe loader retrieves encrypted remote JavaScript from BNB Smart Chain transaction input data for local execution.T1140 · Deobfuscate/Decode Files or InformationEmbedded XOR keys decrypt blockchain-retrieved payload material into executable JavaScript.T1195.002 · Compromise Software Supply ChainMalicious JavaScript was inserted into a legitimate package's development branch exposed as an installable Packagist version.T1204.002 · Malicious FileThe article identifies execution of the poisoned branch as the exposure path and assesses a possible developer-task lure; instructions to victims for this exact version were not observed.
People
Threat Actors
Malware
BeaverTailthe loader ultimately delivered DPRK-linked malware including DEV#POPPER RAT, OmniStealer, and BeaverTail-family payloads. Trend Micro observed a DEV#POPPER RAT variant delivered through this infrastructure,DEV#POPPER RATand overlapping wallet addresses, the loader ultimately delivered DPRK-linked malware including DEV#POPPER RAT, OmniStealer, and BeaverTail-family payloads. Trend Micro observed a DEV#POPPER RAT variant deliveredOmniStealerwallet addresses, the loader ultimately delivered DPRK-linked malware including DEV#POPPER RAT, OmniStealer, and BeaverTail-family payloads. Trend Micro observed a DEV#POPPER RAT variant delivered through this
Vendors
GitHubstable release line did not show the same indicators in our review. This pattern closely resembles recent GitHub Community reports of malicious JavaScript being injected into legitimate developer configuration files asPackagistWe identified malicious obfuscated JavaScript appended to tailwind.js in the Packagist development version dev-drewroberts/feature/test-case of the PHP package roberts/leads.
Products
GitHubstable release line did not show the same indicators in our review. This pattern closely resembles recent GitHub Community reports of malicious JavaScript being injected into legitimate developer configuration files asLaravelThe package itself is a legitimate Laravel package associated with a maintainer, Drew Roberts.Node.jsmalware after identifying obfuscated JavaScript hidden in tailwind.js, including runtime exposure of Node.js internals and immediate execution of a decoded staging payload rather than legitimate TailwindPackagistWe identified malicious obfuscated JavaScript appended to tailwind.js in the Packagist development version dev-drewroberts/feature/test-case of the PHP package roberts/leads.roberts/leadsWe identified malicious obfuscated JavaScript appended to tailwind.js in the Packagist development version dev-drewroberts/feature/test-case of the PHP package roberts/leads.Socket AI ScannerSocket AI Scanner flagged dev-drewroberts/feature/test-case as known malware after identifying obfuscated JavaScript hidden in tailwind.js, including runtime exposure of Node.js internals and immediate execution of aTailwindWe identified malicious obfuscated JavaScript appended to tailwind.js in the Packagist development version dev-drewroberts/feature/test-case of the PHP package roberts/leads.