LWA-2026-11275 confirmed malware
tailwind-plugin-kit@1.3.2
Malicious code in tailwind-plugin-kit (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
tailwind-plugin-kit@1.3.2's main module (index.js) is a remote-code-execution dropper. On load it fetches hxxps://31[.]97[.]137[.]157:45000/icons/109 (with a custom HTTP header bearrtoken:logo) and executes the response body as JavaScript via the Function constructor, injecting Node globals (require, process, Buffer, module, exports) into the eval context so the remote payload can run arbitrary code with full access to the host. The payload is served remotely and is not present in the package. The fetch-and-execute is retried on failure.
- analyzed by
- Leitwacht
- first seen
- Aug 14, 2026, 08:59 AM
- analyzed
- Aug 14, 2026, 08:59 AM
Related advisories
- tailwind-toolkit@1.3.2
- @cdnshell/loader@0.0.1
- bootstrap-custom-ui@5.7.2
- datetime-fmt-xutil@1.0.0
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- semaphore-job-pool@2.2.2
- postcss-initialize-plugin@3.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.