tailwindcss-framer-motion@1.1.3
Malicious code in tailwindcss-framer-motion (npm)
Analysis
This package is a combosquat of the popular tailwindcss and framer-motion libraries. When required, it makes an HTTP GET request to bet[.]slotgambit[.]com/icons/102 and passes the 'credits' field of the JSON response to eval(), executing arbitrary remote code on the installer's machine. Dependencies include node-machine-id (machine fingerprinting), @primno/dpapi (Windows DPAPI credential decryption), better-sqlite3/sqlite3 (local database access), and socket[.]io-client (WebSocket C2 channel) — an infostealer toolkit. C2 host: bet[.]slotgambit[.]com, path: /icons/102.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 03:02 PM
- analyzed
- Jun 14, 2026, 03:03 PM
Related advisories
- svg2text@3.0.0
- super-test-json@1.2.0
- stacknova@1.0.0
- sqrt-bn-enhanced@2.0.9
- spectral-corsair@999.999.1000
- sort-btree@2.1.4
- solanarpclampweb3@1.0.3
- sjs-builders@1.0.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.