tailwind-minanimated@2.3.7
Malicious code in tailwind-minanimated (npm)
Analysis
tailwind-minanimated@2.3.7 is a trojanized Tailwind CSS plugin. Its main entry src/index.js appends an eval(atob(...)) payload that runs on require. The decoded payload is an Ethereum drainer: it builds an RPC client against public endpoints (1rpc[.]io, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io), queries the Blockscout indexer at hxxps://eth[.]blockscout[.]com/api, binary-searches chain blocks for the last transaction from the hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes the recipient address, fetches and XOR-decodes code, and spawns child processes. The payload executes whenever the package is imported.
- analyzed by
- Leitwacht
- first seen
- Aug 31, 2026, 03:54 PM
- analyzed
- Aug 31, 2026, 03:55 PM
Related advisories
- mfaatest@1.0.0
- test__123q1@2.1.3
- grafeno-payments@1.0.0
- grafeno-webhook@1.0.0
- grafeno-billing@1.0.0
- spc_login@1.0.0
- spc-grafeno-login@1.0.0
- test-in-one@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.