tailwind-gutenberg-block-zero@1.0.0
Malicious code in tailwind-gutenberg-block-zero (npm)
Analysis
tailwind-gutenberg-block-zero@1.0.0 is a trojanized clone of a WordPress block-development example. On npm install, the setup.js hook sends the victim's hostname and OS info to api[.]telegram[.]org, then writes a PowerShell script to the temp directory. The PowerShell script installs Scoop, winget, and Deno if not already present, then downloads and executes a remote Deno script from hxxp://172[.]94[.]9[.]157/v028f8cde892b0b74c8[.]js with the -A (all permissions) flag. The remote script is a multi-stage launcher that sets up autorun persistence and runs a main payload. The package also depends on my-tailwind-gutenberg-block (a known malicious package).
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 12:59 PM
- analyzed
- Jul 17, 2026, 01:03 PM
Related advisories
- n8n-nodes-final-mile@1.0.0
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-quick-utils@1.0.0
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-utils-helper@1.0.0
- n8n-nodes-devops-utils@1.0.0
- chai-as-inspired@2.2.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.