LWA-2026-5249 confirmed malware

tailwindcss-animate-builder@2.1.0

Malicious code in tailwindcss-animate-builder (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

The package index.js fetches a second-stage payload from hxxps://bet[.]slotgambit[.]com/icons/104 over HTTPS and executes the response's 'credits' property via new Function() with full Node.js runtime access (require, process, Buffer, module), enabling arbitrary remote code execution on the installer's machine. The package is disguised as a Tailwind CSS forms builder but ships an unrelated dependency set including hardware fingerprinting (node-machine-id), local database access (better-sqlite3, sqlite3), Windows credential API access (@primno/dpapi), WebSocket support (socket[.]io-client), and an HTTP server (express) — providing a complete implant toolkit for the C2-delivered second stage.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 02:03 PM
analyzed
Jun 14, 2026, 02:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.