LWA-2026-5253 MAL-2026-6892 ↗ confirmed malware

tailwindcss-svg-helper@1.17.9

Malicious code in tailwindcss-svg-helper (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

tailwindcss-svg-helper@1.17.9 exports a getPlugin() function that fetches JSON from hxxps://rest-icon-moduler[.]vercel[.]app/icons/102 and executes arbitrary JavaScript from the response's "credits" field via eval(). This is a remote code execution loader — a second-stage payload is fetched from the attacker-controlled Vercel endpoint and executed without integrity verification. The dependency list includes @primno/dpapi (Windows DPAPI credential decryption), better-sqlite3 (browser database access), node-machine-id (device fingerprinting), and socket[.]io-client (websocket transport), indicating the intended post-exploitation payload targets credential theft. The package combosquats the legitimate Tailwind CSS ecosystem with an unrelated name. C2 host: rest-icon-moduler[.]vercel[.]app (HTTPS).

analyzed by
Leitwacht
first seen
Jun 14, 2026, 03:17 PM
analyzed
Jun 14, 2026, 03:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.