my-tailwind-gutenberg-block@0.1.2
Malicious code in my-tailwind-gutenberg-block (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1059.001 · PowerShellT1105 · Ingress Tool TransferT1547.001 · Registry Run Keys / Startup FolderT1071.001 · Web Protocols
Analysis
my-tailwind-gutenberg-block@0.1.2 is a trojanized clone of a WordPress block development example. The package.json install hook runs setup.js, which on Windows installs the Deno runtime and then executes a remote payload fetched from hxxp://172[.]94[.]9[.]157/v028f8cde892b0b74c8[.]js with full system permissions. The payload sets up autorun persistence. The C2 host is 172[.]94[.]9[.]157.
- analyzed by
- Leitwacht
- first seen
- Jul 16, 2026, 08:07 PM
- analyzed
- Jul 16, 2026, 08:07 PM
Related advisories
- mcp-dev-toolkit@1.5.0
- pinokio-redis@1.0.127
- zod-pino434@1.0.127
- crypto-base58@1.0.1
- base58-cli@1.0.0
- pino-zod@1.0.121
- web3-token-helper@1.1.3
- zod-pino@1.0.122
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.