LWA-2026-12138 MAL-2026-16179 ↗ confirmed malware

process-tailwind@1.1.99

Malicious code in process-tailwind (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1059 · Command and Scripting Interpreter

Analysis

process-tailwind@1.1.99 is a remote-code-execution backdoor disguised as a system-information utility. Importing the package auto-starts a detached `node loader.js` process (PID persisted to a `.pid` file so it survives the parent). The loader makes an HTTPS request to hxxps://api[.]npoint[.]io/24c25d5f5fcbb0992a4f, reads a base64-encoded `code` field from the JSON response, decodes it, and executes it via `new Function(...)` with `require`, `__dirname`, `__filename`, `module`, and `exports` in scope — giving the remote operator arbitrary code execution on the installer's machine. The bundled child_process patching is a decoy to appear as a Windows-compatibility helper.

analyzed by
Leitwacht
first seen
Sep 15, 2026, 12:20 AM
analyzed
Sep 15, 2026, 12:21 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.