LWA-2026-11197 confirmed malware

tailwind-toolkit@1.3.2

Malicious code in tailwind-toolkit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1195.002 · Compromise Software Supply Chain

Analysis

tailwind-toolkit@1.3.2 is a combosquat of the tailwindcss package. Its main entry point (index.js) fetches a remote payload from hxxp://31[.]97[.]137[.]157:45000/icons/109 and executes the returned content via the Function constructor with full Node.js access (require, process, Buffer, module), retrying up to 3 times. The actual malicious code is served remotely from the IP 31[.]97[.]137[.]157:45000 rather than shipped in the package, so its behaviour is fully controlled by the remote server. The package also declares dependencies used for credential access and host fingerprinting (@primno/dpapi for Windows DPAPI credential decryption, node-machine-id, sqlite3, socket[.]io-client).

analyzed by
Leitwacht
first seen
Aug 13, 2026, 07:59 PM
analyzed
Aug 13, 2026, 08:01 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.