{"id":"MAL-2026-15904","summary":"Malicious code in tailwind-scrollbar-styles (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2c9c5760f878552d4d2aedb3afc283b64ba99e65acf1e086158afe79a0267ada)\ndist/index.js exports a small tailwind plugin and then runs eval(atob(\"Z2x...\")) on an embedded base64 blob at module load time. The decoded loader queries Ethereum RPC endpoints (1rpc.io/eth, drpc.org, publicnode, blastapi.io) and Blockscout for the most recent transaction sent by hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes four bytes of that transaction's `to` field into an IPv4 address, HTTP-GETs http://\u003cdecoded-ip\u003e:443/0x/cls and http://\u003cdecoded-ip\u003e:443/0x/ls, XOR-decodes the response with literal keys, and executes it via eval() and via a detached `spawn(\"node\", [\"-e\",...], {detached:true, stdio:\"ignore\", windowsHide:true}).unref()`. After first execution the loader reads its own file, locates the `eval(atob(\"Z2x...` region, and rewrites dist/index.js with the region removed, so the malicious line disappears from disk. The Ethereum-transaction-based resolver lets the operator rotate the C2 IP at any time by publishing a new transaction from the controlling address, and the self-erasing stub defeats post-incident inspection of the installed copy.\n","modified":"2026-09-04T04:30:06.559794118Z","published":"2026-09-04T03:45:17Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-019449","import_time":"2026-09-04T04:21:20.748618397Z","modified_time":"2026-09-04T03:45:17Z","sha256":"2c9c5760f878552d4d2aedb3afc283b64ba99e65acf1e086158afe79a0267ada","source":"amazon-inspector","versions":["4.0.3"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tailwind-scrollbar-styles/v/4.0.3"}],"affected":[{"package":{"name":"tailwind-scrollbar-styles","ecosystem":"npm","purl":"pkg:npm/tailwind-scrollbar-styles"},"versions":["4.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"10224bb5a3c323c46f2db5426adc6b4862ab2cce11f433ce4d451fea1485e53257c56c","path":"dist/index.js","sha256":"0eb89136a6553f65d2e4fa3a382276ec53d624750143bc9ba27888fe7ef3aba1"}],"package_integrity":[{"filename":"tailwind-scrollbar-styles-4.0.3.tgz","hashes":{"sha1":"cae64ff2a6a8913da032ab9c930bc2c59ccbc8e8","sha512_sri":"sha512-qVwJGZ9tCwbnTMBkOPVmpzp5ylk4Uz9MazaxT0XxPMSpL0G9ZpsNaSo6GYf35yBCttVeNN6sLddjZ2XumRjwbg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tailwind-scrollbar-styles/MAL-2026-15904.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}