tailwind-utility-kit@1.3.2
Malicious code in tailwind-utility-kit (npm)
Analysis
tailwind-utility-kit@1.3.2 is a remote-code-execution dropper disguised as a Tailwind CSS utility plugin. On import, index.js fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/109 (raw-IP C2, port 45000, custom header "bearrtoken: logo") and executes the returned JSON body as JavaScript via the Function constructor, with Node's require, process, Buffer, module and exports injected so the remote payload has full access to the host. The package also bundles credential-decryption and host-fingerprinting dependencies (better-sqlite3, sqlite3, @primno/dpapi, node-machine-id, socket[.]io-client). The README describes a benign Tailwind plugin and does not match the shipped code.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 03:14 AM
- analyzed
- Aug 15, 2026, 03:14 AM
Related advisories
- hunterone-build-probe-9210@1.0.0
- sbironman@1.0.0
- autbank-core@99.0.0
- axios-fast@1.0.0
- meualelo@99.0.2
- alelo-auth@99.0.2
- alelo-api@99.0.2
- alelo-utils@99.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.