LWA-2026-11652 confirmed malware
tailwindcss-3d-animate@1.2.2
Malicious code in tailwindcss-3d-animate (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel
Analysis
tailwindcss-3d-animate is a trojanized clone of the legitimate tailwindcss-3d plugin. Its main entry (index.js) appends a base64-encoded, obfuscated Ethereum wallet-drainer payload to the real plugin code. On load it decodes and executes a client that reads wallet credentials, queries Ethereum RPC endpoints (blockcsco, drpc[.]org, publicnode, 1rpc, stapi[.]io, mainnet, 0x/ls, 0x/cl), and broadcasts signed transactions via eth_sendRawTransaction, draining the victim's wallet. The payload is obfuscated with an encoded string array and custom decoder.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 09:31 AM
- analyzed
- Aug 27, 2026, 09:34 AM
Related advisories
- dsh-tauri-panel-extension@0.4.0
- hydration-vli-ui@1.0.0
- tsrml612@1.14.0
- chai-as-otc@1.0.5
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
- hydration-dim-ui@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.