LWA-2026-7716 MAL-2026-11765 ↗ confirmed malware

@ornikar/postcss-config@9.1.7

Malicious code in @ornikar/postcss-config (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package @ornikar/postcss-config@9.1.7 is a trojanized version of a legitimate postcss configuration library. The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime and executes a heavily obfuscated 727KB payload file (math_init.js) through it. The payload is obfuscated with javascript-obfuscator-style identifier renaming and contains eval, Function constructor, and child_process invocations. The package's index.js exports are clean postcss configuration helpers, but the preinstall hook runs the obfuscated payload on every install. The only observable network destination in the bootstrap code is github[.]com/oven-sh/bun (the official Bun runtime download).

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:16 AM
analyzed
Aug 4, 2026, 11:22 AM
weekly installs
60

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.