tailwind-opentype@1.2.3
Malicious code in tailwind-opentype (npm)
Analysis
tailwind-opentype@1.2.3 is a trojanized clone of a legitimate Tailwind CSS OpenType plugin. The dist/index.js file re-exports the real plugin code to appear legitimate, but on require() executes an eval(atob(...)) payload that deploys an Ethereum blockchain scanner and wallet drainer. The payload connects to Ethereum RPC endpoints (eth-mainnet[.]public[.]blastapi[.]io and others) to scan for transactions, extracts IP addresses from transaction data, and establishes XOR-encrypted C2 communication over HTTP to hxxp://{extracted-ip}:443/0x/cls and hxxp://{extracted-ip}:443/0x/ls. It spawns detached node child_processes to execute further stages. The package has no repository URL and no license.
- analyzed by
- Leitwacht
- first seen
- Jul 31, 2026, 03:06 PM
- analyzed
- Jul 31, 2026, 03:07 PM
Related advisories
- streak-metrics-core@1.0.0
- supersig@1.0.5
- akamai-sensorv2@1.0.0
- streak-view-core@1.0.0
- streak-grid-core@1.0.0
- streak-int-lib@1.0.0
- @types-beta/sdk@0.1.3
- postcss-motion-utils@3.2.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.