LWA-2026-10735 MAL-2026-13604 ↗ confirmed malware

tailwindcss-motion-advanced@1.0.1

Malicious code in tailwindcss-motion-advanced (npm)

Analysis

A Tailwind CSS animation plugin that is a trojanized clone of the legitimate tailwindcss-motion package. Its index.js loads lib/utils.min.js, which on import queries public Ethereum RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io, or the ETH_RPC_URL env var) to find a transaction sent from the hardcoded address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a. The transaction's recipient field encodes two C2 IP addresses. The code then fetches XOR-encrypted second-stage payloads from hxxp://{ip}:443/0x/cls and hxxp://{ip}:443/0x/ls, decrypts them, and executes them via eval() and a detached `node -e` child process. The C2 rendezvous is derived from the Ethereum blockchain, making the command-and-control infrastructure dynamic and covert.

analyzed by
Leitwacht
first seen
Aug 7, 2026, 10:41 AM
analyzed
Aug 7, 2026, 09:44 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.