process-tailwind@1.1.99
Malicious code in process-tailwind (npm)
Analysis
process-tailwind@1.1.99 is a remote-code-execution backdoor disguised as a system-information utility. Importing the package auto-starts a detached `node loader.js` process (PID persisted to a `.pid` file so it survives the parent). The loader makes an HTTPS request to hxxps://api[.]npoint[.]io/24c25d5f5fcbb0992a4f, reads a base64-encoded `code` field from the JSON response, decodes it, and executes it via `new Function(...)` with `require`, `__dirname`, `__filename`, `module`, and `exports` in scope — giving the remote operator arbitrary code execution on the installer's machine. The bundled child_process patching is a decoy to appear as a Windows-compatibility helper.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 12:20 AM
- analyzed
- Sep 15, 2026, 12:21 AM
Related advisories
- n8n-nodes-buildcheck@1.0.0
- pino-ulid@2.12.3
- @biz44/process-runtime-utils@1.1.10
- @biz44/id44-client@1.1.44
- @biz44/id10-client@1.1.11
- greensaver@1.2.2
- memfd-secret@1.0.0
- open-item-validator@1.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.