LWA-2026-6936 confirmed malware

tailwind-lineclamp@0.4.5

Malicious code in tailwind-lineclamp (npm)

Analysis

tailwind-lineclamp@0.4.5 is a combosquat of the legitimate @tailwindcss/line-clamp Tailwind CSS plugin. The package's src/index.js appends an eval(atob(...)) payload that executes at require-time. At runtime it queries the Tron blockchain (api[.]trongrid[.]io) and Aptos blockchain (fullnode[.]mainnet[.]aptoslabs[.]com) for transaction history on specific wallet addresses — TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP, TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG (Tron) and 0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e, 0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3 (Aptos). The package has no repository and no lifecycle hooks — the payload runs when the module is loaded as a Tailwind plugin.

analyzed by
Leitwacht
first seen
Jul 17, 2026, 02:33 PM
analyzed
Jul 17, 2026, 02:38 PM

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.