LWA-2026-7509 MAL-2026-11487 ↗ confirmed malware

tailwindcss-anim@1.3.3

Malicious code in tailwindcss-anim (npm)

T1059.007 · JavaScriptT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool TransferT1082 · System Information Discovery

Analysis

tailwindcss-anim@1.3.3 is a trojanized clone of a Tailwind CSS animation plugin that contains a blockchain-based C2 implant. The package's index.js appends an eval(atob(...)) payload that decodes to a full remote access tool. At runtime, the implant connects to multiple Ethereum JSON-RPC endpoints (eth[.]drpc[.]org, 1rpc[.]io, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) and scans the blockchain for transactions from wallet address 0x8a33245e5f663d331144330e3665f9a44c243439045f661a. It extracts IP addresses from transaction data fields and establishes XOR-encrypted HTTP communication channels to those IPs for command-and-control. The implant spawns detached node processes to maintain proxy listeners and uses custom HTTP headers (X-Payload-B64, Sec-V) for encrypted C2 traffic. The C2 IPs are dynamically resolved from Ethereum blockchain transactions, making the infrastructure mutable and difficult to block.

analyzed by
Leitwacht
first seen
Aug 2, 2026, 04:25 PM
analyzed
Aug 2, 2026, 04:26 PM
weekly installs
255

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.