LWA-2026-11275 confirmed malware

tailwind-plugin-kit@1.3.2

Malicious code in tailwind-plugin-kit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

tailwind-plugin-kit@1.3.2's main module (index.js) is a remote-code-execution dropper. On load it fetches hxxps://31[.]97[.]137[.]157:45000/icons/109 (with a custom HTTP header bearrtoken:logo) and executes the response body as JavaScript via the Function constructor, injecting Node globals (require, process, Buffer, module, exports) into the eval context so the remote payload can run arbitrary code with full access to the host. The payload is served remotely and is not present in the package. The fetch-and-execute is retried on failure.

analyzed by
Leitwacht
first seen
Aug 14, 2026, 08:59 AM
analyzed
Aug 14, 2026, 08:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.