LWA-2026-11277 confirmed malware

postcss-initialize-provider@3.0.4

Malicious code in postcss-initialize-provider (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

postcss-initialize-provider@3.0.4 is a trojanized clone of the legitimate postcss-initial plugin. The package's index.js contains the real postcss plugin code followed by a large obfuscated payload that executes on require(). The payload spawns child processes, reads the ETH_RPC_URL environment variable, and issues Ethereum JSON-RPC calls (eth_getBlock, eth_getBalance) against a list of RPC endpoints. It beacons to C2 infrastructure reachable via the hosts stapi[.]io and ut[.]com/api, with a command path under :443/0x/cl, and handles transaction/address data (strings 'address=' and 'transactio'). The obfuscated code also performs gzip/deflate/brotli decompression of responses, consistent with a multi-stage crypto-drainer implant.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 12:13 PM
analyzed
Aug 14, 2026, 12:16 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.