LWA-2026-11313 confirmed malware

tailwind-utility-kit@1.3.2

Malicious code in tailwind-utility-kit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.001 · Credentials In FilesT1082 · System Information Discovery

Analysis

tailwind-utility-kit@1.3.2 is a remote-code-execution dropper disguised as a Tailwind CSS utility plugin. On import, index.js fetches a payload from hxxps://31[.]97[.]137[.]157:45000/icons/109 (raw-IP C2, port 45000, custom header "bearrtoken: logo") and executes the returned JSON body as JavaScript via the Function constructor, with Node's require, process, Buffer, module and exports injected so the remote payload has full access to the host. The package also bundles credential-decryption and host-fingerprinting dependencies (better-sqlite3, sqlite3, @primno/dpapi, node-machine-id, socket[.]io-client). The README describes a benign Tailwind plugin and does not match the shipped code.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 03:14 AM
analyzed
Aug 15, 2026, 03:14 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.