tailwindcss-motion-advanced@1.0.1
Malicious code in tailwindcss-motion-advanced (npm)
Analysis
A Tailwind CSS animation plugin that is a trojanized clone of the legitimate tailwindcss-motion package. Its index.js loads lib/utils.min.js, which on import queries public Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io, or the ETH_RPC_URL env var) to find a transaction sent from the hardcoded address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a. The transaction's recipient field encodes two C2 IP addresses. The code then fetches XOR-encrypted second-stage payloads from hxxp://{ip}:443/0x/cls and hxxp://{ip}:443/0x/ls, decrypts them, and executes them via eval() and a detached `node -e` child process. The C2 rendezvous is derived from the Ethereum blockchain, making the command-and-control infrastructure dynamic and covert.
- analyzed by
- Leitwacht
- first seen
- Aug 7, 2026, 10:41 AM
- analyzed
- Aug 7, 2026, 09:44 PM
Related advisories
- map-streak-kit@1.0.0
- platform-ui-colors@35.8.1
- dolyame-ui-buttonstore@35.8.1
- streak-kit-map@1.0.0
- streak-map-cache@1.0.0
- streak-cache-map@1.0.0
- constructor-blocks-mailings@35.5.7
- ded-aa-common-ded-aa-common-core@35.1.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.