tailwindcss-hide-scrollbar@2.5.4
Malicious code in tailwindcss-hide-scrollbar (npm)
Analysis
tailwindcss-hide-scrollbar@2.5.4 is a trojanized clone of the legitimate tailwind scrollbar-hide plugin. The package's main entry dist/index.js appends an obfuscated payload (encoded string array with a custom decoder) to the genuine plugin code. On module load the payload executes an Ethereum RPC client that connects to blockchain endpoints (drpc[.]org, stapi[.]io, blockscout, herum-rpc, h.blockcso, pc[.]io/eth, ut[.]com/api, h-mainnet) and issues eth_getBalance, eth_getTransactionCount, eth_getCode, eth_getStorageAt, eth_blockNumber and eth_getBlockByNumber queries, using an 'x-payload-' HTTP header and ':443/0x/cl' and ':443/0x/ls' request paths. The payload also uses child_process and zlib gunzip/base64 decoding stages, consistent with a wallet-drainer / blockchain-recon implant that reads on-chain wallet state and exfiltrates it over HTTP/HTTPS.
- analyzed by
- Leitwacht
- first seen
- Aug 6, 2026, 02:17 PM
- analyzed
- Aug 6, 2026, 02:18 PM
- weekly installs
- 232
Related advisories
- nhdxzthponv5@1.0.0
- streak-cache-map@1.0.0
- app-api-sdk@2.1.7
- app-kst-engine@2.1.6
- dlab_workshop@1.0.3
- @lizhao1/memorax-code-internal@0.1.2
- @zahlen/checkout-react@0.1.1
- foodi@99.99.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.