LWA-2026-5251 confirmed malware

tailwindcss-devtools@1.4.0

Malicious code in tailwindcss-devtools (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1082 · System Information Discovery

Analysis

This package is a combosquat on the Tailwind CSS ecosystem (tailwindcss-devtools). Its entry point (package/index.js), when required, automatically fetches a second-stage payload from bet[.]slotgambit[.]com/icons/<token> via the fetch() API and executes the response through new Function() with full access to Node.js built-ins (require, process, console, Buffer). This gives the remote server arbitrary code execution on the installer's machine. The package also depends on tailwindcss-popups (a known malicious package), node-machine-id (device fingerprinting), and socket[.]io-client. The C2 host is bet[.]slotgambit[.]com.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 02:33 PM
analyzed
Jun 14, 2026, 02:34 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.