tailwind-anim@1.2.5
Malicious code in tailwind-anim (npm)
Analysis
tailwind-anim@1.2.5 is a trojanized clone of a Tailwind CSS animation plugin. The package ships a legitimate-looking plugin in index.js with a hidden eval(atob()) payload appended. At runtime, the payload monitors the Ethereum blockchain by making JSON-RPC calls (eth_blockNumber, eth_getBlockByNumber, eth_getTransactionCount) to multiple public RPC endpoints (1rpc[.]io, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io). It searches for transactions from a hardcoded address, extracts the recipient address from matching transactions, and uses the first 4 bytes of that address as a C2 IP (port 80) and the next 4 bytes as a secondary C2 IP (port 80/443). It then establishes XOR-encrypted HTTP communication with the C2, spawns a detached node process for persistence, and attempts to fetch and execute additional payloads from the C2 at paths /0x/cls and /0x/ls.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:24 PM
- analyzed
- Aug 2, 2026, 04:30 PM
- weekly installs
- 269
Related advisories
- tinkoff-boxy-desktop-icons-horizontal@20.1.8
- bnpl-blocks-independent-bnpl-search@20.2.9
- tinkoff-statist-browser-typed-client-sme.platform.web.companyprofile.metrics@20.2.7
- dolyame-boxy-independent-bnpl-info-images@20.7.2
- statist-browser-typed-client-mb.product.sme.cards@20.5.9
- taiga-ui-proprietary-navigation@20.1.2
- pvm-autodoc@20.4.6
- pfa-errors@20.4.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.