mountly-tailwind@0.1.3
Malicious code in mountly-tailwind (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File
Analysis
mountly-tailwind ships a 4.5MB index.js consisting of a single eval() call wrapping a ROT-cipher-encoded numeric array, with no readable JS outside the decoder, despite the package being a CSS design-tokens library with no JS entry point in its exports map. The eval uses a custom ROT-cipher decoder to reconstruct and execute an obfuscated second-stage payload at module-load time — a worm-injected, compromised publish.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:47 PM
- analyzed
- Jun 10, 2026, 08:49 PM
Related advisories
- postcss-processor-utils@1.0.3
- dolyame-boxy-mobile-bnpl-card-panel@35.3.4
- bnpl-blocks-atom-desktop-bnpl-text@35.2.5
- bigops-products-bnpl@35.2.9
- devplatform-create-nx-spa@35.4.9
- @ornikar/renovate-config@9.0.8
- bigops-call-history@35.8.9
- bigops-auth-interceptor@35.7.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.