LWA-2026-6934 confirmed malware

tailwind-animationfound@2.3.7

Malicious code in tailwind-animationfound (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool Transfer

Analysis

Combosquat TailwindCSS animation plugin that executes a wallet-drainer payload on require(). The package's src/index.js appends an eval(atob(...)) call containing obfuscated JavaScript that queries Tron (api[.]trongrid[.]io) and Aptos (fullnode[.]mainnet[.]aptoslabs[.]com) blockchain RPC endpoints for specific wallet addresses: TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP, TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG (Tron), 0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e, and 0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3 (Aptos). The runtime behaviour confirms DNS resolution and HTTPS requests to both blockchain fullnode APIs to check wallet transaction history — a reconnaissance step typical of wallet-draining malware.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 02:32 PM
analyzed
Jul 17, 2026, 02:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.