core-tailwindcss-utility@3.7.1
Malicious code in core-tailwindcss-utility (npm)
Analysis
core-tailwindcss-utility@3.7.1 is a combosquat of the tailwindcss package whose main entry point (index.js) is a remote-code-execution dropper. On load it fetches hxxps://31[.]97[.]137[.]157:45000/icons/108 and executes the response body's `credits` field via the Function constructor with full Node.js context (require, process, Buffer, module, globalThis), giving the remotely-served code unrestricted access to the host. The package bundles dependencies consistent with a credential-stealing implant: @primno/dpapi (Windows DPAPI credential decryption), node-machine-id (host fingerprinting), socket[.]io-client (command/control channel), and better-sqlite3/sqlite3 (local database access). C2 endpoint: 31[.]97[.]137[.]157:45000, path /icons/.
- analyzed by
- Leitwacht
- first seen
- Aug 17, 2026, 02:31 PM
- analyzed
- Aug 17, 2026, 02:32 PM
Related advisories
- runtime-health@1.0.1
- @evial/runtime-health@1.0.0
- @evial/init-helper-djkwt@1.0.0
- @evial/runtime-utils@1.0.0
- colorpicker-ui@1.2.6
- harmony-app-toolkit@21.0.0
- tailwind-utility-kit@1.3.2
- hunterone-build-probe-9210@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.