Trusted Dev Branch Becomes a Malware Delivery Path
The trap is the trusted package path, not a fake package name. A legitimate Packagist/GitHub project had its installable dev branch poisoned, so ordinary “install the official package” instincts miss the real risk: the branch you pull can carry the payload.
Socket.dev found malicious JavaScript appended to `tailwind.js` in the `dev-drewroberts/feature/test-case` version of `roberts/leads`, a Laravel package. The loader reached public blockchain RPC services on TRON, Aptos, and BNB Smart Chain, pulled encrypted payload material, decrypted it, and ran it, with the stable release line not showing the same indicators in review.
That delivery channel is harder to shut down than a single domain or repository, and it makes dev-branch installs from public registries a persistent exposure class.