LWA-2026-11398 confirmed malware

core-tailwindcss-utility@3.7.1

Malicious code in core-tailwindcss-utility (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

core-tailwindcss-utility@3.7.1 is a combosquat of the tailwindcss package whose main entry point (index.js) is a remote-code-execution dropper. On load it fetches hxxps://31[.]97[.]137[.]157:45000/icons/108 and executes the response body's `credits` field via the Function constructor with full Node.js context (require, process, Buffer, module, globalThis), giving the remotely-served code unrestricted access to the host. The package bundles dependencies consistent with a credential-stealing implant: @primno/dpapi (Windows DPAPI credential decryption), node-machine-id (host fingerprinting), socket[.]io-client (command/control channel), and better-sqlite3/sqlite3 (local database access). C2 endpoint: 31[.]97[.]137[.]157:45000, path /icons/.

analyzed by
Leitwacht
first seen
Aug 17, 2026, 02:31 PM
analyzed
Aug 17, 2026, 02:32 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.