tailwind-toolkit@1.3.2
Malicious code in tailwind-toolkit (npm)
Analysis
tailwind-toolkit@1.3.2 is a combosquat of the tailwindcss package. Its main entry point (index.js) fetches a remote payload from hxxp://31[.]97[.]137[.]157:45000/icons/109 and executes the returned content via the Function constructor with full Node.js access (require, process, Buffer, module), retrying up to 3 times. The actual malicious code is served remotely from the IP 31[.]97[.]137[.]157:45000 rather than shipped in the package, so its behaviour is fully controlled by the remote server. The package also declares dependencies used for credential access and host fingerprinting (@primno/dpapi for Windows DPAPI credential decryption, node-machine-id, sqlite3, socket[.]io-client).
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 07:59 PM
- analyzed
- Aug 13, 2026, 08:01 PM
Related advisories
- @cdnshell/loader@0.0.1
- bootstrap-custom-ui@5.7.2
- datetime-fmt-xutil@1.0.0
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- semaphore-job-pool@2.2.2
- postcss-initialize-plugin@3.0.4
- cc-skills-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.