@ornikar/postcss-config@9.1.7
Malicious code in @ornikar/postcss-config (npm)
Analysis
The package @ornikar/postcss-config@9.1.7 is a trojanized version of a legitimate postcss configuration library. The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime and executes a heavily obfuscated 727KB payload file (math_init.js) through it. The payload is obfuscated with javascript-obfuscator-style identifier renaming and contains eval, Function constructor, and child_process invocations. The package's index.js exports are clean postcss configuration helpers, but the preinstall hook runs the obfuscated payload on every install. The only observable network destination in the bootstrap code is github[.]com/oven-sh/bun (the official Bun runtime download).
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:16 AM
- analyzed
- Aug 4, 2026, 11:22 AM
- weekly installs
- 60
Related advisories
- @ornikar/prismic-components@0.0.8
- @ornikar/rollup-plugin-postcss@2.0.10
- @ornikar/react-native-svg-transformer@1.0.10
- @ornikar/lerna-config@11.0.6
- @ornikar/react-modern-calendar-datepicker@3.2.6
- @ornikar/babel-preset-react@6.1.6
- @ornikar/apollo-link-timeout@1.4.3
- @onereach/ts-memoize@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.