LWA-2026-7303 MAL-2026-12222 ↗ confirmed malware

tailwind-opentype@1.2.3

Malicious code in tailwind-opentype (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool Transfer

Analysis

tailwind-opentype@1.2.3 is a trojanized clone of a legitimate Tailwind CSS OpenType plugin. The dist/index.js file re-exports the real plugin code to appear legitimate, but on require() executes an eval(atob(...)) payload that deploys an Ethereum blockchain scanner and wallet drainer. The payload connects to Ethereum RPC endpoints (eth-mainnet[.]public[.]blastapi[.]io and others) to scan for transactions, extracts IP addresses from transaction data, and establishes XOR-encrypted C2 communication over HTTP to hxxp://{extracted-ip}:443/0x/cls and hxxp://{extracted-ip}:443/0x/ls. It spawns detached node child_processes to execute further stages. The package has no repository URL and no license.

analyzed by
Leitwacht
first seen
Jul 31, 2026, 03:06 PM
analyzed
Jul 31, 2026, 03:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.