tailwindcss-fluid-styles@2.0.7
Malicious code in tailwindcss-fluid-styles (npm)
Analysis
The tailwindcss-fluid-styles package (a Tailwind plugin) ships a base64-encoded payload in src/index.js that executes on require. The payload queries the Ethereum blockchain (via eth[.]blockscout[.]com and several public RPC endpoints) for the latest transaction sent from wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes the transaction recipient address into an IP address, then fetches XOR-encrypted second-stage payloads from that IP over HTTP (paths /0x/cls and /0x/ls) and executes them by spawning a detached `node -e` subprocess. The code also rewrites its own source file to remove the embedded payload after execution.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 12:31 PM
- analyzed
- Sep 2, 2026, 12:34 PM
Related advisories
- bt2-api-gateway-node-js@999.0.0
- tailwindcss-3d-styles@1.2.2
- @divineubg/divine@1.1.2
- tailwind-modernanimation@2.3.8
- zenntechinc-cli@1.6.4
- chai-as-mno@1.0.5
- fetch-page-assets@1.2.13
- @syncraft-labs/core@0.4.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.