tailwind-extension-kit@1.3.2
Malicious code in tailwind-extension-kit (npm)
Analysis
tailwind-extension-kit@1.3.2 is a combosquat of "tailwind" that executes remote code on require. Its main entry point index.js fetches hxxp://31[.]97[.]137[.]157:45000/icons/109 and runs the returned JSON field `credits` through the Function constructor with full Node.js globals injected (require, process, Buffer, global, setTimeout), giving the remote payload arbitrary code execution in the installer's environment. The fetch is wrapped in a retry loop that re-requests on failure. The package also declares unrelated dependencies (axios, express, better-sqlite3, socket[.]io-client, node-machine-id) inconsistent with its stated Tailwind-utilities purpose.
- analyzed by
- Leitwacht
- first seen
- Aug 17, 2026, 03:16 PM
- analyzed
- Aug 17, 2026, 03:17 PM
Related advisories
- core-tailwindcss-utility@3.7.1
- runtime-health@1.0.1
- mutex-core@2.1.2
- rand-tx-sdk@1.0.6
- tyepescript-core@1.0.0
- typecript-cli@1.0.0
- typescipt-core@1.0.0
- typescriptt-core@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.