LWA-2026-4203 MAL-2026-5619 ↗ confirmed malware

tailwind-typography-plus@2.1.0

Malicious code in tailwind-typography-plus (npm)

T1059.007 · JavaScriptT1027 · Obfuscated Files or InformationT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

tailwind-typography-plus@2.1.0 masquerades as a Tailwind typography plugin and steganographically encodes a payload inside font-metrics.json as font-metric ratio arrays. On require, index.js decodes the ratios back to bytes and executes them via new Function('require','process','Buffer','console', source), granting full Node.js API access to the decoded code with no lifecycle hook needed. The decoded payload issues a GET request to hxxp://194[.]11[.]226[.]41:4000/d/zRlY7_JxvFY8_Zhhu8ih24iW_dT5Rb_9/agent-linux-amd64 to fetch a second-stage binary. A commented "STEALTH PAYLOAD AREA" marker is left in styles.js.

analyzed by
Leitwacht
first seen
Jun 11, 2026, 07:04 AM
analyzed
Jun 11, 2026, 07:06 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.