LWA-2026-6865 MAL-2026-10761 ↗ confirmed malware

my-tailwind-gutenberg-block@0.1.2

Malicious code in my-tailwind-gutenberg-block (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1071.001 · Web Protocols

Analysis

my-tailwind-gutenberg-block@0.1.2 is a trojanized clone of a WordPress block development example. The package.json install hook runs setup.js, which on Windows installs the Deno runtime and then executes a remote payload fetched from hxxp://172[.]94[.]9[.]157/v028f8cde892b0b74c8[.]js with full system permissions. The payload sets up autorun persistence. The C2 host is 172[.]94[.]9[.]157.

analyzed by
Leitwacht
first seen
Jul 16, 2026, 08:07 PM
analyzed
Jul 16, 2026, 08:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.