MAL-2026-14038
Dashboard / Malicious Package / MAL-2026-14038
MAL-2026-14038
Summary: Malicious code in tailwind-toolkit (npm)
Details: Source: amazon-inspector (afeb355b3088d1c03dbbb5a60c1afea5afbe3a384f50417ae6cfa7340d8c072d) The package presents itself as a Tailwind CSS plugin, but its default export (which runs when users register it in tailwind.config) issues an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/109 and passes the response body's `credits` field into `new Function(require, module, exports,...)` for execution in the installer's Node process. The destination URL is assembled from split variables and disguised with CDN/icon vocabulary (an unused `iconDomain` map referencing cloudflare/fastly/akamai, a `bearrtoken: "logo"` header, a response field named `credits`), while the actual host is an unrelated bare IP on a non-standard port. The package also declares dependencies on @primno/dpapi (Windows DPAPI credential decryption), better-sqlite3/sqlite3 (browser cookie and Login Data databases), and node-machine-id, indicating the retrieved payload is a browser-credential stealer. The remote host and executed bytes are fully attacker-controlled and unrelated to the advertised Tailwind CSS purpose.
Affected packages
Package
Name: tailwind-toolkit
Purl: pkg:npm/tailwind-toolkit
Affected ranges
Type: N/A
Events:
