LWA-2026-5252 MAL-2026-6891 ↗ confirmed malware

tailwindcss-framer-motion@1.1.3

Malicious code in tailwindcss-framer-motion (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1082 · System Information DiscoveryT1552.001 · Credentials In Files

Analysis

This package is a combosquat of the popular tailwindcss and framer-motion libraries. When required, it makes an HTTP GET request to bet[.]slotgambit[.]com/icons/102 and passes the 'credits' field of the JSON response to eval(), executing arbitrary remote code on the installer's machine. Dependencies include node-machine-id (machine fingerprinting), @primno/dpapi (Windows DPAPI credential decryption), better-sqlite3/sqlite3 (local database access), and socket[.]io-client (WebSocket C2 channel) — an infostealer toolkit. C2 host: bet[.]slotgambit[.]com, path: /icons/102.

analyzed by
Leitwacht
first seen
Jun 14, 2026, 03:02 PM
analyzed
Jun 14, 2026, 03:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.