stylelint-standard@1.2.0
Malicious code in stylelint-standard (npm)
Analysis
stylelint-standard@1.2.0 is a combosquat of the legitimate stylelint CSS linter. On installation, its postinstall script (bin.js) — heavily obfuscated with javascript-obfuscator — decrypts a 3MB AES-CBC encrypted payload stored in docs/manifest using the crypto and zlib modules, then executes the unpacked second-stage implant. The package bundles node-fetch and form-data for outbound data exfiltration, and sqlite3, mammoth, officeparser, and rtf-parser for harvesting local credentials and sensitive documents. The package is disguised with husky git-hooks documentation as a cover to appear legitimate.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 09:47 AM
- analyzed
- Jun 14, 2026, 09:49 AM
Related advisories
- macos-ci-utils@1.0.1
- react-next-dom@1.1.7
- node-pino@2.3.2
- chai-utils-test@4.5.4
- autotel-mongoose@2.0.5
- autotel-mongoose@3.0.1
- autotel-mongoose@6.0.1
- autotel-mongoose@4.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.