LWA-2026-11652 confirmed malware

tailwindcss-3d-animate@1.2.2

Malicious code in tailwindcss-3d-animate (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1552.001 · Credentials In FilesT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

tailwindcss-3d-animate is a trojanized clone of the legitimate tailwindcss-3d plugin. Its main entry (index.js) appends a base64-encoded, obfuscated Ethereum wallet-drainer payload to the real plugin code. On load it decodes and executes a client that reads wallet credentials, queries Ethereum RPC endpoints (blockcsco, drpc[.]org, publicnode, 1rpc, stapi[.]io, mainnet, 0x/ls, 0x/cl), and broadcasts signed transactions via eth_sendRawTransaction, draining the victim's wallet. The payload is obfuscated with an encoded string array and custom decoder.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 09:31 AM
analyzed
Aug 27, 2026, 09:34 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.