fix(security): remove Ethereum-C2 loader from packages/ui postcss config - #8
polylane[bot] wants to merge 2 commits into
Conversation
Co-authored-by: polylane[bot] <277585245+polylane[bot]@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Tip Expected to resolve the linked issue. Linked issue: iss_0b3a89a61001v9vmif901191 — Ethereum-C2 loader committed in packages/ui/postcss.config.mjs (build-host RCE and failing production builds) Checked payweave-web's build logs: main (fdd1a05) carries the loader's Also considered · 2 refuted
payweave-web production build log (main, fdd1a05) — loader error in packages/ui/postcss.config.mjs · web:build: ./packages/ui/postcss.config.mjs:10:7219
web:build: Module not found: Can't resolve ('-e' | <dynamic>)Full log (14 of 168 lines)web:build: ▲ Next.js 16.2.10 (Turbopack)
web:build: Creating an optimized production build ...
web:build: Turbopack build encountered 1 warnings:
web:build: ./packages/ui/postcss.config.mjs:10:7219
web:build: Module not found: Can't resolve ('-e' | <dynamic>)
web:build: > 10 | ...+code),spawn("node",["-e",env+code],{detached:!0,stdio:"ignore",windowsHide:!0}).unref(...
web:build: | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
web:build: Import trace:
web:build: postcss:
web:build: ./packages/ui/postcss.config.mjs
web:build: ./apps/web/postcss.config.mjs
web:build: https://nextjs.org/docs/messages/module-not-found
web:build: ✓ Compiled successfully in 27.7s
web:build: Running TypeScript ...payweave-web build log at head SHA c173f10 — same project, loader removed · web:build: ✓ Compiled successfully in 14.4s
web:build: ✓ Generating static pages using 1 worker (14/14) in 521msFull log (13 of 84 lines)web:build: > web@0.0.1 build /vercel/path0/apps/web
web:build: > next build
web:build: ▲ Next.js 16.2.10 (Turbopack)
web:build: [MDX] generated files in 33.310027999999875ms
web:build: Creating an optimized production build ...
web:build: ✓ Compiled successfully in 14.4s
web:build: Running TypeScript ...
web:build: Finished TypeScript in 4.8s ...
web:build: Collecting page data using 1 worker ...
web:build: Generating static pages using 1 worker (0/14) ...
web:build: ✓ Generating static pages using 1 worker (14/14) in 521ms
web:build: Finalizing page optimization ...
web:build: Running onBuildComplete from VercelAnalysed against 1 Project and 1 repository
Polylane analysed Did this help? React 👍 or 👎 so the next review is sharper. |
|
This pull request is waiting on a decision: merge it if the change is still wanted, or close it if the fix is no longer needed. Either one settles it. It was opened on 2026-09-18 and has had no new activity for a week. If nothing happens on it within a week, Polylane closes it and keeps the branch, so reopening it brings the change back exactly as it stands. @phoenixdahdev, the change touches what you own, so the review is with you. |
Fixes: Committed Ethereum-C2 malware in six phoenixdahdev repos: build-host RCE and failed production deploys
An obfuscated loader had been committed into the UI package's postcss.config.mjs. Next.js evaluates that file during every build, so the loader ran on the build machine and, where the bundler rejected its dynamic require, the production build failed. Restoring the file to its original Tailwind configuration removes the malicious code and lets the build run as before.
What caused this
Affected:
int_0b2300ad4001ia0oribh5vgeWhy this fix
packages/ui/postcss.config.mjsonmainwas 7,824 bytes and contained the known EtherHiding-style C2 loader (IOC stringseth.blockscout.com,x-payload-b64,0x/cls,0x/ls, plus acreateRequire(import.meta.url)preamble). Reading the committed bytes showed the legitimate Tailwind PostCSS config wrapped by that injected preamble and a ~7.6 KB payload appended afterexport default config;.The change strips the injected preamble and the appended payload, leaving only the original config, which loads and exports the
@tailwindcss/postcssplugin that the package actually depends on. A repository-wide search confirms the only othercreateRequireuses are legitimate:apps/web/postcss.config.mjsis a 144-byte re-export of this config, and thetsup.cli.config.tshit is a comment.apps/webbuilds successfully on the cleaned tree.This PR removes the payload from the current tree only. It remains in the repository's git history and must be purged, and because the loader ran on build hosts, any secret reachable at build time in this project should be rotated. That work, and the same removal in the other affected repositories, is tracked on the incident.
1 file changed (+1/-5)
packages/ui/postcss.config.mjs: modified, +1/-5Repository lint:
pnpm run lint(declared in package.json) fails over the whole repository (the declared target takes no file arguments), so the failure is not attributed to this change and did not block it; run it before merging.Lint output
Generated by Polylane. You can ask follow-ups by mentioning @polylane in a comment.