LWA-2026-11900 confirmed malware

tailwindcss-ratio-styles@0.3.2

Malicious code in tailwindcss-ratio-styles (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

tailwindcss-ratio-styles@0.3.2 is a trojanized clone of the legitimate tailwindcss-aspect-ratio plugin. Its main entry point src/index.js appends a remote-code downloader to the genuine plugin code: on module load it fetches hxxp://23[.]27[.]245[.]100/index[.]js over plain HTTP, writes the response to ./inout.js in the current directory, and executes it via require(). This runs arbitrary remote code on any project that imports the package. C2/download host: 23[.]27[.]245[.]100 (port 80), path /index.js.

analyzed by
Leitwacht
first seen
Sep 5, 2026, 08:20 AM
analyzed
Sep 5, 2026, 08:20 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.