postcss-animate-css-vars@2.0.3
Malicious code in postcss-animate-css-vars (npm)
Analysis
postcss-animate-css-vars is a trojanized PostCSS plugin that executes a multi-stage payload when loaded. The file src/normalize-options.js is heavily obfuscated (javascript-obfuscator) and, upon require(), writes a temporary .cjs file to the system temp directory containing the obfuscated payload, then spawns a detached child process (detached:true, windowsHide:true, stdio:'ignore') that re-executes the payload. The payload also fetches remote content and evaluates it dynamically. The package has no lifecycle hooks — the malicious code runs when any build pipeline loads the PostCSS plugin. The publisher email does not match the claimed author, indicating account takeover.
- analyzed by
- Leitwacht
- first seen
- Jul 30, 2026, 09:10 PM
- analyzed
- Jul 30, 2026, 09:10 PM
Related advisories
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-task-runner@1.0.0
- ai-pro-sdk@2.0.3
- paperclip2@1.0.0
- compose-logger-stand@1.0.126
- bandkit@1.0.7
- yoshino_s_test_evil@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.