mountly-tailwind@0.1.3
Malicious code in mountly-tailwind (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1204.002 · Malicious File
Analysis
mountly-tailwind ships a 4.5MB index.js consisting of a single eval() call wrapping a ROT-cipher-encoded numeric array, with no readable JS outside the decoder, despite the package being a CSS design-tokens library with no JS entry point in its exports map. The eval uses a custom ROT-cipher decoder to reconstruct and execute an obfuscated second-stage payload at module-load time — a worm-injected, compromised publish.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 08:47 PM
- analyzed
- Jun 10, 2026, 08:49 PM
Related advisories
- postcss-processor-utils@1.0.3
- nebulaai-sdk@1.0.0
- chromatitle@1.0.0
- @syncraft-labs/vue@0.4.1
- @wizloft/harness-kernel@0.1.1-alpha.3
- @wizloft/harness-context@0.1.1-alpha.3
- @wizloft/harness@0.1.1-alpha.3
- cc-skills-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.