tailwindcss-anim@1.3.3
Malicious code in tailwindcss-anim (npm)
Analysis
tailwindcss-anim@1.3.3 is a trojanized clone of a Tailwind CSS animation plugin that contains a blockchain-based C2 implant. The package's index.js appends an eval(atob(...)) payload that decodes to a full remote access tool. At runtime, the implant connects to multiple Ethereum JSON-RPC endpoints (eth[.]drpc[.]org, 1rpc[.]io, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) and scans the blockchain for transactions from wallet address 0x8a33245e5f663d331144330e3665f9a44c243439045f661a. It extracts IP addresses from transaction data fields and establishes XOR-encrypted HTTP communication channels to those IPs for command-and-control. The implant spawns detached node processes to maintain proxy listeners and uses custom HTTP headers (X-Payload-B64, Sec-V) for encrypted C2 traffic. The C2 IPs are dynamically resolved from Ethereum blockchain transactions, making the infrastructure mutable and difficult to block.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:25 PM
- analyzed
- Aug 2, 2026, 04:26 PM
- weekly installs
- 255
Related advisories
- sme-auth-core@20.9.2
- bigops-voximplant@20.8.5
- tailwind-custom-forms@0.5.2
- twork-data-services-sme-operations-authorizations@20.8.9
- tinkoff-statist-browser-typed-client-jumptaxi.feature.contacts@20.6.6
- tms-x-headers@20.2.9
- tinkoff-mutual-mgm-form@20.2.9
- tcb-web-copy-to-clipboard@20.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.