Hi Andy,
Very good find! One of the artifacts to which the malicious code was appended (`postcss.config.js`) even matches. The WOFF one doesn’t.It looks like the maintainer/upstream dev was compromised with PolinRider or a variant of that. https://github.com/OpenSourceMalware/PolinRider
It’s definitely possible that the upstream dev has been compromised and hasn’t even noticed.
Regards Claudia
OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
