LWA-2026-7294 MAL-2026-12418 ↗ confirmed malware

postcss-animate-css-vars@2.0.3

Malicious code in postcss-animate-css-vars (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059 · Command and Scripting InterpreterT1082 · System Information DiscoveryT1071 · Application Layer ProtocolT1105 · Ingress Tool Transfer

Analysis

postcss-animate-css-vars is a trojanized PostCSS plugin that executes a multi-stage payload when loaded. The file src/normalize-options.js is heavily obfuscated (javascript-obfuscator) and, upon require(), writes a temporary .cjs file to the system temp directory containing the obfuscated payload, then spawns a detached child process (detached:true, windowsHide:true, stdio:'ignore') that re-executes the payload. The payload also fetches remote content and evaluates it dynamically. The package has no lifecycle hooks — the malicious code runs when any build pipeline loads the PostCSS plugin. The publisher email does not match the claimed author, indicating account takeover.

analyzed by
Leitwacht
first seen
Jul 30, 2026, 09:10 PM
analyzed
Jul 30, 2026, 09:10 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.