tailwind-typography-plus@2.1.0
Malicious code in tailwind-typography-plus (npm)
Analysis
tailwind-typography-plus@2.1.0 masquerades as a Tailwind typography plugin and steganographically encodes a payload inside font-metrics.json as font-metric ratio arrays. On require, index.js decodes the ratios back to bytes and executes them via new Function('require','process','Buffer','console', source), granting full Node.js API access to the decoded code with no lifecycle hook needed. The decoded payload issues a GET request to hxxp://194[.]11[.]226[.]41:4000/d/zRlY7_JxvFY8_Zhhu8ih24iW_dT5Rb_9/agent-linux-amd64 to fetch a second-stage binary. A commented "STEALTH PAYLOAD AREA" marker is left in styles.js.
- analyzed by
- Leitwacht
- first seen
- Jun 11, 2026, 07:04 AM
- analyzed
- Jun 11, 2026, 07:06 AM
Related advisories
- myria-core-sdk@0.0.248
- mountly@0.2.2
- mountly-tailwind@0.1.3
- postcss-processor-utils@1.0.3
- fastify-addon@5.1.0
- metrica-node@2.4.5
- vite-config-optimizer@1.1.4
- chai-utils-test@4.5.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.