postcss-initialize-provider@3.0.4
Malicious code in postcss-initialize-provider (npm)
Analysis
postcss-initialize-provider@3.0.4 is a trojanized clone of the legitimate postcss-initial plugin. The package's index.js contains the real postcss plugin code followed by a large obfuscated payload that executes on require(). The payload spawns child processes, reads the ETH_RPC_URL environment variable, and issues Ethereum JSON-RPC calls (eth_getBlock, eth_getBalance) against a list of RPC endpoints. It beacons to C2 infrastructure reachable via the hosts stapi[.]io and ut[.]com/api, with a command path under :443/0x/cl, and handles transaction/address data (strings 'address=' and 'transactio'). The obfuscated code also performs gzip/deflate/brotli decompression of responses, consistent with a multi-stage crypto-drainer implant.
- analyzed by
- Leitwacht
- first seen
- Aug 14, 2026, 12:13 PM
- analyzed
- Aug 14, 2026, 12:16 PM
Related advisories
- mutex-thread@1.3.0
- meualelo@99.0.2
- notafollower1226@1.0.0
- alelo-auth@99.0.2
- alelo-api@99.0.2
- alelo-utils@99.0.0
- alelo-services@99.0.0
- alelo-common@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.