tailwind-scrollbar-styles@4.0.3
Malicious code in tailwind-scrollbar-styles (npm)
Analysis
tailwind-scrollbar-styles@4.0.3 is a tailwindcss plugin whose dist/index.js contains an eval(atob(...)) payload that runs when the module is imported. The decoded payload queries Ethereum RPC endpoints (eth[.]blockscout[.]com, 1rpc[.]io, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) for transactions sent from wallet 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes the recipient address of the latest transaction to derive a C2 IP address, then fetches XOR-encoded second-stage payloads from hxxp://<ip>:443/0x/cls and hxxp://<ip>:443/0x/ls and executes them by spawning detached `node -e` processes (windowsHide, stdio ignored). The payload also rewrites its own source file to remove the eval(atob) block after execution, evading inspection. The package is a trojanized clone of the legitimate tailwind-scrollbar-styles plugin with the implant injected into the main entry point.
- analyzed by
- Leitwacht
- first seen
- Sep 2, 2026, 12:41 PM
- analyzed
- Sep 2, 2026, 12:41 PM
Related advisories
- tailwind-container-queries@0.1.1
- tailwindcss-3d-styles@1.2.2
- devplatform-spa-plugin-module-loader@35.8.5
- entropyeasybots@2.0.2
- @marketfront/bannerpopup@7.0.0
- @digitalcnzz/embedded-sdk@1.0.7
- util-free-ports@3.1.2
- stringfy-utils-kit@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.