{"id":"MAL-2026-12217","summary":"Malicious code in tailwind-animate-plugin (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7eb20d422c7053793a78e3d898bef2d97269318be88f147d60c7d036d2d23144)\nindex.js appends a large base64-encoded, unicode-escaped payload after ~11 KB of whitespace padding, executed via eval(atob('...')) whenever the package is required (main = index.js). The decoded payload queries Ethereum RPC endpoints (eth.blockscout.com/api, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) for transactions from 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, extracts two IPv4 addresses from a tx.to field, then HTTP-GETs http://\u003cresolved-ip\u003e:443/0x/cls and http://\u003cresolved-ip\u003e:443/0x/ls, XOR-decrypts the response, and executes the resulting code via spawn('node', ['-e', payload], {detached: true, stdio: 'ignore', windowsHide: true}).unref(). Sensitive identifiers ('http', 'child_process', 'spawn', 'POST', 'HEAD', 'x-payload-b64', RPC URLs, target address) are stored as \\uXXXX escapes to defeat casual scanning. The package presents itself as a Tailwind CSS animation plugin; the dropper is hidden behind the benign plugin body. Any consumer of this package receives arbitrary attacker-controlled code execution on the host at require time, with the C2 host resolvable on-chain and thus resistant to takedown.\n","modified":"2026-08-05T10:06:28.902012843Z","published":"2026-08-05T09:04:44Z","database_specific":{"malicious-packages-origins":[{"versions":["1.1.0"],"id":"IN-MAL-2026-014535","import_time":"2026-08-05T09:28:23.231028421Z","modified_time":"2026-08-05T09:04:44Z","sha256":"7eb20d422c7053793a78e3d898bef2d97269318be88f147d60c7d036d2d23144","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tailwind-animate-plugin/v/1.1.0"}],"affected":[{"package":{"name":"tailwind-animate-plugin","ecosystem":"npm","purl":"pkg:npm/tailwind-animate-plugin"},"versions":["1.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-Rr+TfwHdkbFFgUd74ggcM6k0iKEPaqxhGfxK7f7KrFc8rYJ/GE9c9SsNQGZzQkHP4S8uKB/2JanIxQdlv/r2iw==","sha1":"e7e3e97f964cceac95a72ce2d331e2f829839872"},"filename":"tailwind-animate-plugin-1.1.0.tgz"}],"evidence_files":[{"path":"index.js","sha256":"b269c93d22ca67aa134c1f47d798446d45a7ab53be4152ca86e89a9bfdde3df3","tlsh":"31726fe2969a7647cf035526fe6f07ce1b3904b176ac1fa97013987223c9c5826ad31f"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tailwind-animate-plugin/MAL-2026-12217.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}