tailwind-modernanimation@2.3.8
Malicious code in tailwind-modernanimation (npm)
Analysis
tailwind-modernanimation@2.3.8 ships a hidden C2 loader in its main entry src/index.js. On module load it decodes an embedded base64 payload that queries Ethereum RPC endpoints and the eth[.]blockscout[.]com indexer to locate a transaction from wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, derives two IPv4 C2 addresses from the transaction's recipient bytes, then fetches XOR-encrypted second-stage payloads over HTTP from hxxp://{ip}:80 and hxxp://{ip}:443/0x/cls and /0x/ls. The fetched payloads are decrypted with a charcode XOR loop and executed either via eval or by spawning a detached `node -e` child process (stdio ignored, window hidden, unref'd). The package is otherwise a Tailwind CSS animation plugin, so the loader runs silently when the plugin is required.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 03:49 PM
- analyzed
- Aug 31, 2026, 03:49 PM
Related advisories
- cbc97b7a@1.1787999998.0
- fb-cards-form-no-resident-information@20.4.4
- crypto-base58@1.0.1
- zhuanhua@1.1.99
- @dilxzphrine/baileys@1.0.0
- xeiko-cdn@1.0.0
- mev-shield@1.4.2
- zenntechinc-cli@1.6.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.