tailwind-aspect@0.4.2
Malicious code in tailwind-aspect (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
A trojanized clone of the tailwindcss-aspect-ratio plugin. On module load, src/index.js downloads a JavaScript payload from hxxp://23[.]27[.]245[.]100/index[.]js, writes it to ./inout.js in the current directory, and executes it via require(). Any application that imports the package triggers the remote code fetch and execution.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 11:20 PM
- analyzed
- Sep 3, 2026, 11:21 PM
Related advisories
- tailwind-contact-forms@0.5.12
- hydration-ui-pkg@1.0.0
- @bx-ui-framework/authentication@1.2.0
- @stellarshift/chain-metadata@1.0.1
- @stellarshift/evm-address-kit@1.0.1
- @stellarshift/token-units@1.0.1
- @stellarshift/abi-tools@1.0.1
- tailwind-scrollbar-styles@4.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.