MAL-2026-12417
Malicious code in post-css-transfer (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f62ccc235772a34a28d870f349489698c167e3d636a196f310fe24c1ce1d4ef4) post-css-transfer is a typosquat of postcss whose main entry lib/postcss.js has an obfuscated IIFE appended after the legitimate module code. On require/import, the appended block resolves a command-and-control IP by reading transactions of Ethereum address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a via public Ethereum RPC endpoints and the eth.blockscout.com API, decodes two IPv4 addresses from the transaction recipient bytes, fetches an XOR-encrypted payload over HTTP from those hosts (delivered in an x-payload-b64 header), and executes the decrypted payload via eval() and a detached `node -e` child process. Network, execution, and identifier primitives (http, child_process, spawn, the Ethereum address, method and header names) are written as \uXXXX escapes and hidden behind ~1KB of whitespace padding after `module.exports = postcss;` to evade casual review.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for post-css-transfer (npm). Pin to a known-safe version or switch to an alternative.