LWA-2026-11900 confirmed malware
tailwindcss-ratio-styles@0.3.2
Malicious code in tailwindcss-ratio-styles (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
tailwindcss-ratio-styles@0.3.2 is a trojanized clone of the legitimate tailwindcss-aspect-ratio plugin. Its main entry point src/index.js appends a remote-code downloader to the genuine plugin code: on module load it fetches hxxp://23[.]27[.]245[.]100/index[.]js over plain HTTP, writes the response to ./inout.js in the current directory, and executes it via require(). This runs arbitrary remote code on any project that imports the package. C2/download host: 23[.]27[.]245[.]100 (port 80), path /index.js.
- analyzed by
- Leitwacht
- first seen
- Sep 5, 2026, 08:20 AM
- analyzed
- Sep 5, 2026, 08:20 AM
Related advisories
- @baipiaojuntuan/reverseproxy-fm@1.0.9
- ulid-intel@2.12.3
- tailwind-aspect@0.4.2
- tailwind-contact-forms@0.5.12
- hydration-ui-pkg@1.0.0
- @bx-ui-framework/authentication@1.2.0
- @stellarshift/chain-metadata@1.0.1
- @stellarshift/evm-address-kit@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.