Vendor
Packagist
- First Reported
- May 31, 2026
- Latest Reported
- May 31, 2026
Reported Context (1)
- We identified malicious obfuscated JavaScript appended to tailwind.js in the Packagist development version dev-drewroberts/feature/test-case of the PHP package roberts/leads. Famous Chollima-Linked Campaign Targets PHP Developers Through Malicious Packagist Branch
Malware (3)
People (1)
Threat Actors (1)
MITRE ATT&CK (7)
Vendors (1)
Products (7)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.