Gii
All skills
securityGii

Build-Config Malware Scanner

Detect the hidden-payload supply-chain attack in postcss, tailwind, next, vite, and babel configs before you build.

Published by Gii1 installsv1.0.02 KBUpdated Aug 13, 2026

Build-config malware scanner

Scans build-config files for obfuscated JavaScript appended after the legitimate export and hidden with hundreds of spaces of padding. These configs run on every build, so the payload executes when you build. It flags known obfuscation fingerprints in executable files and absurdly long padded lines in any file. See the SKILL.md inside the bundle for full usage, remediation steps, and prevention via a session-start hook.

SKILL.md

namemalware-config-scan
descriptionScan a project's build-config files (postcss, tailwind, next, vite, babel) for a hidden-payload supply-chain attack where obfuscated JavaScript is appended after the legitimate export and padded with hundreds of spaces to hide it past the editor's right edge. Use before running npm install or build on any repo you did not write, or when auditing a codebase for supply-chain compromise.

Changelog

Initial release.