tailwind-anime@1.1.0
Malicious code in tailwind-anime (npm)
Analysis
tailwind-anime@1.1.0 is a trojanized Tailwind CSS plugin. The package's index.js appends an eval(atob()) payload after a legitimate-looking animation plugin. At runtime, the payload connects to multiple Ethereum JSON-RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to scan blockchain blocks for transactions involving a hardcoded target address. It extracts IP addresses from transaction data, establishes a XOR-encrypted C2 communication channel, and spawns detached child processes executing eval'd code. The package has no repository and its only purpose is to execute this blockchain-scanning and C2 payload on install.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 07:42 AM
- analyzed
- Aug 4, 2026, 07:42 AM
- weekly installs
- 253
Related advisories
- bigops-auth-interceptor@35.7.2
- bigops-header-tabs@35.8.2
- bigops-auth-provider-interceptor@35.8.3
- bigops-external-auth@35.1.6
- bigops-info-notices@35.9.8
- bigops-chat-files-hub-client@35.4.6
- bigops-chat-tmsg@35.8.5
- bigops-data-storage@35.7.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.