LWA-2026-10902 confirmed malware

postcss-initial-provider@3.0.4

Malicious code in postcss-initial-provider (npm)

T1102 · Web ServiceT1105 · Ingress Tool TransferT1059.007 · JavaScriptT1573 · Encrypted ChannelT1071.001 · Web Protocols

Analysis

postcss-initial-provider@3.0.4 is a trojanized clone of the postcss-initial plugin with a blockchain-resolved C2 implant injected into index.js. On module load it queries public Ethereum RPC endpoints (1rpc[.]io, eth[.]drpc[.]org, publicnode, blastapi) and process.env.ETH_RPC_URL to scan blocks for transactions from the attacker's wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. It derives two C2 IP addresses from the first 8 bytes of the transaction's `to` address, then fetches XOR-encrypted second-stage payloads from hxxp://{ip}:443/0x/cls and hxxp://{ip}:443/0x/ls, decrypts them, and executes them both via eval and via a detached `node -e` child process. The attacker rotates C2 infrastructure by publishing new Ethereum transactions.

analyzed by
Leitwacht
first seen
Aug 10, 2026, 02:34 AM
analyzed
Aug 10, 2026, 02:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.