LWA-2026-7376 MAL-2026-12417 ↗ confirmed malware

post-css-transfer@0.0.1

Malicious code in post-css-transfer (npm)

Analysis

post-css-transfer@0.0.1 is a trojanized clone of the legitimate postcss package. On require(), it queries multiple Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to find the latest block, then searches for a transaction from attacker wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a. The 'to' field of that transaction encodes two C2 IP addresses. The payload fetches XOR-encrypted second-stage payloads from those IPs at paths /0x/cls and /0x/ls, decrypts them with key "q4FZkxX{!h,Sr3=@", and executes them via eval() inline and via detached hidden node subprocesses (spawn with detached:true, windowsHide:true, stdio:ignore). This is a blockchain-based C2 implant using Ethereum transactions as a dead-drop for C2 address distribution.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 08:39 AM
analyzed
Aug 2, 2026, 08:40 AM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.