From 969e9e827dab2be4f614789fcfb154689c8e4f61 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 28 Aug 2026 08:53:00 +0000 Subject: [PATCH] Remove obfuscated RCE payload from postcss.config.mjs and restore .gitignore postcss.config.mjs carried an obfuscated JavaScript payload appended after the legitimate config, hidden behind a long run of spaces on the closing line so it sits off-screen in an editor. Restored to its pre-tampering content. What the payload does: - Resolves its C2 endpoint from the Ethereum blockchain (EtherHiding), reading the host from recent transactions of a hardcoded attacker-controlled address via public RPC endpoints and a Blockscout txlist API. - Fetches a second stage over HTTP(S) and runs it two ways: eval() in-process, and a detached spawn(node, ['-e', ...]) with stdio 'ignore' and windowsHide, unref'd so it outlives the parent. postcss.config.mjs executes_on_every_build_and_dev_server_start, so this ran on developer machines and in CI. .gitignore was rewritten by the same commit: line endings converted, the .env entry deleted, and a config.bat entry added. Removing .env from .gitignore stages local secrets to become committable. Restored to its pre-tampering revision. The payload first arrived in fe8a61d_("license",_2025-04-15). --- .gitignore | 109 +++++++++++++++------------------------------ postcss.config.mjs | 5 --- 2 files changed, 36 insertions(+), 78 deletions(-) diff --git a/.gitignore b/.gitignore index 1ce4daa..fd3dbb5 100644 --- a/.gitignore +++ b/.gitignore @@ -1,73 +1,36 @@ -# See https://help.github.com/articles/ignoring-files/ for more about ignoring files. - - - -# dependencies - -/node_modules - -/.pnp - -.pnp.js - -.yarn/install-state.gz - - - -# testing - -/coverage - - - -# next.js - -/.next/ - -/out/ - - - -# production - -/build - - - -# misc - -.DS_Store - -*.pem - - - -# debug - -npm-debug.log* - -yarn-debug.log* - -yarn-error.log* - - - -# local env files - -.env*.local - - - -# vercel - -.vercel - - - -# typescript - -*.tsbuildinfo - -next-env.d.ts - -config.bat +# See https://help.github.com/articles/ignoring-files/ for more about ignoring files. + +# dependencies +/node_modules +/.pnp +.pnp.js +.yarn/install-state.gz + +# testing +/coverage + +# next.js +/.next/ +/out/ + +# production +/build + +# misc +.DS_Store +*.pem + +# debug +npm-debug.log* +yarn-debug.log* +yarn-error.log* + +# local env files +.env*.local + +# vercel +.vercel + +# typescript +*.tsbuildinfo +next-env.d.ts diff --git a/postcss.config.mjs b/postcss.config.mjs index 24dce6d..1a69fd2 100644 --- a/postcss.config.mjs +++ b/postcss.config.mjs @@ -1,13 +1,8 @@ /** @type {import('postcss-load-config').Config} */ - const config = { - plugins: { - tailwindcss: {}, - }, - }; export default config;