LWA-2026-7719 MAL-2026-11775 ↗ confirmed malware

@ornikar/rollup-plugin-postcss@2.0.10

Malicious code in @ornikar/rollup-plugin-postcss (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027.002 · Software PackingT1105 · Ingress Tool Transfer

Analysis

A trojanized clone of the legitimate rollup-plugin-postcss package. The preinstall hook (setup.mjs) downloads a Bun binary from github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/ and executes a heavily-obfuscated 727KB payload (math_init.js) through it. The dist/index.js contains a verbatim copy of the real plugin code as camouflage. The obfuscated payload is executed at install time via the preinstall lifecycle hook.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:16 AM
analyzed
Aug 4, 2026, 11:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.