LWA-2026-5229 confirmed malware

stylelint-standard@1.2.0

Malicious code in stylelint-standard (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1573 · Encrypted ChannelT1140 · Deobfuscate/Decode Files or InformationT1027 · Obfuscated Files or InformationT1005 · Data from Local SystemT1204.002 · Malicious File

Analysis

stylelint-standard@1.2.0 is a combosquat of the legitimate stylelint CSS linter. On installation, its postinstall script (bin.js) — heavily obfuscated with javascript-obfuscator — decrypts a 3MB AES-CBC encrypted payload stored in docs/manifest using the crypto and zlib modules, then executes the unpacked second-stage implant. The package bundles node-fetch and form-data for outbound data exfiltration, and sqlite3, mammoth, officeparser, and rtf-parser for harvesting local credentials and sensitive documents. The package is disguised with husky git-hooks documentation as a cover to appear legitimate.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 09:47 AM
analyzed
Jun 14, 2026, 09:49 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.