LWA-2026-5248 MAL-2026-7026 ↗ confirmed malware

tailwind-core@4.3.0

Malicious code in tailwind-core (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

tailwind-core@4.3.0 is a combosquat of the legitimate tailwindcss CSS framework, published by a known supply-chain attacker account. The package ships a functional CSS compiler as cover but contains a base64 decoding function (Buffer.from base64 to string) paired with a new Function(code) call that evaluates decoded content — a dormant eval-decoder channel for executing hidden payloads. The package is published under the name tailwind-core to trick developers mistyping tailwindcss, on a GitHub repository at github[.]com/QaLemos/tailwind-core.git — an unaffiliated user, not the official tailwindlabs organization.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 02:03 PM
analyzed
Jun 14, 2026, 02:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.