tailwindcss-svg-helper@1.17.9
Malicious code in tailwindcss-svg-helper (npm)
Analysis
tailwindcss-svg-helper@1.17.9 exports a getPlugin() function that fetches JSON from hxxps://rest-icon-moduler[.]vercel[.]app/icons/102 and executes arbitrary JavaScript from the response's "credits" field via eval(). This is a remote code execution loader — a second-stage payload is fetched from the attacker-controlled Vercel endpoint and executed without integrity verification. The dependency list includes @primno/dpapi (Windows DPAPI credential decryption), better-sqlite3 (browser database access), node-machine-id (device fingerprinting), and socket[.]io-client (websocket transport), indicating the intended post-exploitation payload targets credential theft. The package combosquats the legitimate Tailwind CSS ecosystem with an unrelated name. C2 host: rest-icon-moduler[.]vercel[.]app (HTTPS).
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 03:17 PM
- analyzed
- Jun 14, 2026, 03:18 PM
Related advisories
- tailwindcss-framer-motion@1.1.3
- tailwindcss-devtools@1.4.0
- tailwindcss-animate-builder@2.1.0
- tailmagic@2.3.2
- tabbables@45.0.0
- system-driver@1.0.1
- sycm-vendors@55.0.0
- swplayer-react-sl@1.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.