chiprook
← Security
SecuritySeptember 17, 2026, 16:39

Malicious npm Package Found in Job Take-Home Test

A developer discovered malicious code in transitive dependency @aaron205whitmore/postcss-animate-utils@1.0.2, pulled via animatecss-tailwind-adapter@2.0.6 in a take-home test from Antfarm DAO. The package connects to 153.75.81.2:1224 and can execute arbitrary JavaScript via new Function.

Malicious npm Package Found in Job Take-Home Test
#Npm#Antfarm
Read next
Security

NIO ES8 in Norwegian Mine: 90% of Traffic Went to Chinese Servers

Security

Fake LastPass Installers Pushed Kernel Driver That Killed 145 Security Tools

Security

Hacktron details attack chain that compromised OpenAI employee accounts

Security

iOS 27 lets apps ask your iPhone if you're being scammed