Malicious code in postcss-selector-minify (npm)
-= Per source details. Do not edit below this line.=-
Package is published as postcss-selector-minify (a word-order permutation of cssnano's widely used postcss-minify-selectors) and registers itself to PostCSS under the legitimate plugin's id postcss-minify-selectors, so consumers who mistype or misremember the cssnano plugin name receive a different publisher's package that self-identifies as the real one. On require(), the main entry performs a bare side-effect import of layerd-unit-codec-parser/cjs-runner (return value discarded) before any other work, and replaces the de-facto-standard postcss-selector-parser with layerd-unit-codec-parser/selector-parser (the standard parser is demoted to devDependencies). layerd-unit-codec-parser is an obscure package whose name has no relation to CSS or PostCSS; the /cjs-runner submodule path is shaped specifically to execute code on load. Installing this package silently pulls layerd-unit-codec-parser into the consumer's dependency tree and runs its cjs-runner module on every require of the wrapper.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준