tailwindcss-devtools@1.4.0
Malicious code in tailwindcss-devtools (npm)
Analysis
This package is a combosquat on the Tailwind CSS ecosystem (tailwindcss-devtools). Its entry point (package/index.js), when required, automatically fetches a second-stage payload from bet[.]slotgambit[.]com/icons/<token> via the fetch() API and executes the response through new Function() with full access to Node.js built-ins (require, process, console, Buffer). This gives the remote server arbitrary code execution on the installer's machine. The package also depends on tailwindcss-popups (a known malicious package), node-machine-id (device fingerprinting), and socket[.]io-client. The C2 host is bet[.]slotgambit[.]com.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 02:33 PM
- analyzed
- Jun 14, 2026, 02:34 PM
Related advisories
- system-driver@1.0.1
- system-drive@1.0.0
- swagger-express-validators@1.0.0
- svg2text@3.0.0
- super-test-json@1.2.0
- st-pathhelper@1.0.0
- stacknova@1.0.0
- sqrt-bn-enhanced@2.0.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.