LWA-2026-11802 MAL-2026-15634 ↗ confirmed malware

tailwind-minanimated@2.3.7

Malicious code in tailwind-minanimated (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1552.001 · Credentials In Files

Analysis

tailwind-minanimated@2.3.7 is a trojanized Tailwind CSS plugin. Its main entry src/index.js appends an eval(atob(...)) payload that runs on require. The decoded payload is an Ethereum drainer: it builds an RPC client against public endpoints (1rpc[.]io, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io), queries the Blockscout indexer at hxxps://eth[.]blockscout[.]com/api, binary-searches chain blocks for the last transaction from the hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes the recipient address, fetches and XOR-decodes code, and spawns child processes. The payload executes whenever the package is imported.

analyzed by
Leitwacht
first seen
Aug 31, 2026, 03:54 PM
analyzed
Aug 31, 2026, 03:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.