Malicious npm Package Found in Job Take-Home Test
A developer discovered malicious code in transitive dependency @aaron205whitmore/postcss-animate-utils@1.0.2, pulled via animatecss-tailwind-adapter@2.0.6 in a take-home test from Antfarm DAO. The package connects to 153.75.81.2:1224 and can execute arbitrary JavaScript via new Function.
- Malicious package @aaron205whitmore/postcss-animate-utils@1.0.2 with SHA-1 183f39ef3531ad688f168c81e25b528b55630d67
- Code contacts 153.75.81.2:1224 and executes base64 payload via new Function
- Repository also contained an npm authentication token
- No C2 connection or system persistence found
Read next
Security