LWA-2026-10625 MAL-2026-13424 ↗ confirmed malware

tailwindcss-hide-scrollbar@2.5.4

Malicious code in tailwindcss-hide-scrollbar (npm)

T1059.007 · JavaScriptT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

tailwindcss-hide-scrollbar@2.5.4 is a trojanized clone of the legitimate tailwind scrollbar-hide plugin. The package's main entry dist/index.js appends an obfuscated payload (encoded string array with a custom decoder) to the genuine plugin code. On module load the payload executes an Ethereum RPC client that connects to blockchain endpoints (drpc[.]org, stapi[.]io, blockscout, herum-rpc, h.blockcso, pc[.]io/eth, ut[.]com/api, h-mainnet) and issues eth_getBalance, eth_getTransactionCount, eth_getCode, eth_getStorageAt, eth_blockNumber and eth_getBlockByNumber queries, using an 'x-payload-' HTTP header and ':443/0x/cl' and ':443/0x/ls' request paths. The payload also uses child_process and zlib gunzip/base64 decoding stages, consistent with a wallet-drainer / blockchain-recon implant that reads on-chain wallet state and exfiltrates it over HTTP/HTTPS.

analyzed by
Leitwacht
first seen
Aug 6, 2026, 02:17 PM
analyzed
Aug 6, 2026, 02:18 PM
weekly installs
232

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.