LWA-2026-7695 MAL-2026-12027 ↗ confirmed malware

tailwind-anime@1.1.0

Malicious code in tailwind-anime (npm)

Analysis

tailwind-anime@1.1.0 is a trojanized Tailwind CSS plugin. The package's index.js appends an eval(atob()) payload after a legitimate-looking animation plugin. At runtime, the payload connects to multiple Ethereum JSON-RPC endpoints (1rpc[.]io/eth, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to scan blockchain blocks for transactions involving a hardcoded target address. It extracts IP addresses from transaction data, establishes a XOR-encrypted C2 communication channel, and spawns detached child processes executing eval'd code. The package has no repository and its only purpose is to execute this blockchain-scanning and C2 payload on install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 07:42 AM
analyzed
Aug 4, 2026, 07:42 AM
weekly installs
253

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.