LWA-2026-4019 MAL-2026-5261 ↗ confirmed malware

mountly-tailwind@0.1.3

Malicious code in mountly-tailwind (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File

Analysis

mountly-tailwind ships a 4.5MB index.js consisting of a single eval() call wrapping a ROT-cipher-encoded numeric array, with no readable JS outside the decoder, despite the package being a CSS design-tokens library with no JS entry point in its exports map. The eval uses a custom ROT-cipher decoder to reconstruct and execute an obfuscated second-stage payload at module-load time — a worm-injected, compromised publish.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 08:47 PM
analyzed
Jun 10, 2026, 08:49 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.