LWA-2026-6890 MAL-2026-11044 ↗ confirmed malware

tailwind-gutenberg-block-zero@1.0.0

Malicious code in tailwind-gutenberg-block-zero (npm)

Analysis

tailwind-gutenberg-block-zero@1.0.0 is a trojanized clone of a WordPress block-development example. On npm install, the setup.js hook sends the victim's hostname and OS info to api[.]telegram[.]org, then writes a PowerShell script to the temp directory. The PowerShell script installs Scoop, winget, and Deno if not already present, then downloads and executes a remote Deno script from hxxp://172[.]94[.]9[.]157/v028f8cde892b0b74c8[.]js with the -A (all permissions) flag. The remote script is a multi-stage launcher that sets up autorun persistence and runs a main payload. The package also depends on my-tailwind-gutenberg-block (a known malicious package).

analyzed by
Leitwacht
first seen
Jul 17, 2026, 12:59 PM
analyzed
Jul 17, 2026, 01:03 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.