postcss-initial-provider@3.0.4
Malicious code in postcss-initial-provider (npm)
Analysis
postcss-initial-provider@3.0.4 is a trojanized clone of the postcss-initial plugin with a blockchain-resolved C2 implant injected into index.js. On module load it queries public Ethereum RPC endpoints (1rpc[.]io, eth[.]drpc[.]org, publicnode, blastapi) and process.env.ETH_RPC_URL to scan blocks for transactions from the attacker's wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. It derives two C2 IP addresses from the first 8 bytes of the transaction's `to` address, then fetches XOR-encrypted second-stage payloads from hxxp://{ip}:443/0x/cls and hxxp://{ip}:443/0x/ls, decrypts them, and executes them both via eval and via a detached `node -e` child process. The attacker rotates C2 infrastructure by publishing new Ethereum transactions.
- analyzed by
- Leitwacht
- first seen
- Aug 10, 2026, 02:34 AM
- analyzed
- Aug 10, 2026, 02:34 AM
Related advisories
- godot-kit@1.0.1786316795
- fsbrowse@0.2.28
- cryptostock@1.0.0
- envpack-conf@1.0.1
- iconova-react@1.30.1
- kit-map-streak@1.0.0
- @kolbo/mcp@1.57.1
- map-streak-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.