tailwindcss-scrollbar-hide@2.2.6
Malicious code in tailwindcss-scrollbar-hide (npm)
Analysis
tailwindcss-scrollbar-hide@2.2.6 is a trojanized clone of the legitimate tailwind plugin: the real scrollbar-hide plugin code is present, but dist/index.js appends an eval(atob(...)) payload. The decoded payload is an Ethereum wallet-drainer / C2 implant. It queries Ethereum JSON-RPC endpoints (eth-blockscout[.]com, eth-drpc[.]org, eth[.]llamarpc[.]com, eth-mainnet[.]public[.]blastapi[.]io, 1rpc[.]io/eth) to read blockchain state and locate a target address, derives two C2 IP addresses from the transaction recipient address, and spawns a detached node process (detached, stdio ignored, windowsHide) that beacons to hxxp://<ip>:443/0x/cls and hxxp://<ip>:443/0x/ls. Traffic is XOR-encrypted with a key derived from the target address. The implant runs on module load with no user interaction.
- analyzed by
- Leitwacht
- first seen
- Aug 5, 2026, 07:36 AM
- analyzed
- Aug 5, 2026, 07:40 AM
- weekly installs
- 123
Related advisories
- @tuluax/errb@3.0.1
- webdev-conf@5.0.0
- tailwind-anime@1.1.0
- bigops-auth-interceptor@35.7.2
- bigops-header-tabs@35.8.2
- bigops-auth-provider-interceptor@35.8.3
- bigops-external-auth@35.1.6
- bigops-info-notices@35.9.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.