tailwind-animationfound@2.3.7
Malicious code in tailwind-animationfound (npm)
Analysis
Combosquat TailwindCSS animation plugin that executes a wallet-drainer payload on require(). The package's src/index.js appends an eval(atob(...)) call containing obfuscated JavaScript that queries Tron (api[.]trongrid[.]io) and Aptos (fullnode[.]mainnet[.]aptoslabs[.]com) blockchain RPC endpoints for specific wallet addresses: TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP, TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG (Tron), 0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e, and 0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3 (Aptos). The runtime behaviour confirms DNS resolution and HTTPS requests to both blockchain fullnode APIs to check wallet transaction history — a reconnaissance step typical of wallet-draining malware.
- analyzed by
- Leitwacht
- first seen
- Jul 17, 2026, 02:32 PM
- analyzed
- Jul 17, 2026, 02:35 PM
Related advisories
- og-boost-br@1.0.0
- crypto-javas@2.0.8
- n8n-nodes-http-probe@1.0.0
- n8n-nodes-probe@1.0.0
- n8n-nodes-api-finder@1.0.0
- n8n-nodes-port-scanner@1.0.0
- n8n-nodes-net-utils@1.0.0
- n8n-nodes-utils-helper@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.