wind_css@4.0.13
Malicious code in wind_css (npm)
Analysis
Package wind_css (a combosquat of Tailwind CSS) runs a preinstall script (dist/util.js) that performs extensive anti-analysis checks — detecting virtual machines by MAC address prefixes (00:05:69, 00:50:56, 00:0c:29, 08:00:27, 00:03:ff, and others), checking CPU core count, system memory, uptime, and hostname against blocklisted prefixes. If the checks pass and the environment is deemed a real machine, the script connects to a remote server over HTTPS and eval()'s the response, enabling arbitrary remote code execution. Runtime analysis observed DNS queries to ip[.]sb (an IP geolocation service) for environment fingerprinting prior to C2 connection. The package's repository URL is spoofed (pointing to an unrelated project).
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 03:43 AM
- analyzed
- Jun 16, 2026, 03:46 AM
Related advisories
- unicode-colors@4.1.4
- hex-type@3.0.2
- farming-tools-12@4.68.54
- os-ulid-void@3.0.2
- wallet-sdk-9@3.7.73
- solana-web3-stable@1.0.0
- solana-rpc-client@1.0.0
- solana-web3-patched@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.