LWA-2026-5502 confirmed malware

wind_css@4.0.13

Malicious code in wind_css (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1497 · Virtualization/Sandbox EvasionT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Package wind_css (a combosquat of Tailwind CSS) runs a preinstall script (dist/util.js) that performs extensive anti-analysis checks — detecting virtual machines by MAC address prefixes (00:05:69, 00:50:56, 00:0c:29, 08:00:27, 00:03:ff, and others), checking CPU core count, system memory, uptime, and hostname against blocklisted prefixes. If the checks pass and the environment is deemed a real machine, the script connects to a remote server over HTTPS and eval()'s the response, enabling arbitrary remote code execution. Runtime analysis observed DNS queries to ip[.]sb (an IP geolocation service) for environment fingerprinting prior to C2 connection. The package's repository URL is spoofed (pointing to an unrelated project).

analyzed by
Leitwacht
first seen
Jun 16, 2026, 03:43 AM
analyzed
Jun 16, 2026, 03:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.