tailwindcss-animate-builder@2.1.0
Malicious code in tailwindcss-animate-builder (npm)
Analysis
The package index.js fetches a second-stage payload from hxxps://bet[.]slotgambit[.]com/icons/104 over HTTPS and executes the response's 'credits' property via new Function() with full Node.js runtime access (require, process, Buffer, module), enabling arbitrary remote code execution on the installer's machine. The package is disguised as a Tailwind CSS forms builder but ships an unrelated dependency set including hardware fingerprinting (node-machine-id), local database access (better-sqlite3, sqlite3), Windows credential API access (@primno/dpapi), WebSocket support (socket[.]io-client), and an HTTP server (express) — providing a complete implant toolkit for the C2-delivered second stage.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 02:03 PM
- analyzed
- Jun 14, 2026, 02:05 PM
Related advisories
- tailmagic@2.3.2
- tabbables@45.0.0
- system-driver@1.0.1
- sycm-vendors@55.0.0
- swplayer-react-sl@1.0.5
- super-useful-omega-package-123@0.2.1
- strutil-kit@1.0.0
- streamvault@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.