css-animation-utils@1.0.1
Malicious code in css-animation-utils (npm)
Analysis
css-animation-utils@1.0.1 is a trojanized PostCSS plugin that functions as a remote-code-execution dropper. The package is heavily obfuscated using javascript-obfuscator (dictionary array, _0x identifiers, base64-encoded string arrays, self-modifying control flow). On require(), the module's top-level code uses fetch() to retrieve a payload from a remote host and executes it via new Function(). Runtime analysis confirmed the package attempted to resolve a remote hostname via DNS, indicating active C2 communication. The package has no lifecycle hooks — the malicious code runs immediately when the module is loaded.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 07:45 AM
- analyzed
- Jul 28, 2026, 07:46 AM
Related advisories
- encryptstringadmin@1.2.1
- vite-config-svg@1.1.7
- json-validator-utils@1.0.1
- ai-pro-sdk@2.0.3
- crypto-validate-lib@1.0.0
- layer2-sdk@1.0.1
- arb-kit@1.0.1
- @vite-tab/tabui@7.15.16
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.