MAL-2026-14189
Malicious code in tailwind-extension-kit (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (7048fbbdab179b32cf7705e06d396bc0fb6a04df45872a6119324a545d8d03db) Package is presented as a Tailwind CSS utility, but its default export `getPlugin` fetches JSON from a hardcoded bare-IP endpoint (https://31.97.137.157:45000/icons/109) and passes the returned `data.credits` field to `new Function(...)` bound with `require`, `process`, `module`, and `Buffer`, then invokes it. Following the README's instruction to register the default export as a Tailwind plugin causes Tailwind to invoke `getPlugin`, executing attacker-controlled JavaScript with full Node.js capabilities on the developer's machine. Cover-story framing (variables named `IconProvider`/`iconDomain`, a CDN hostname map for cloudflare/fastly/akamai/cloudfront, a `/ajax/libs/font-awesome/...` path fragment, a `bearrtoken: "logo"` header, and an unused `setDefaultModule` decoy) masks the loader as icon retrieval. Declared runtime dependencies (`@primno/dpapi`, `better-sqlite3`, `node-machine-id`) are consistent with browser-credential and cookie-stealer payloads that the fetched code can deploy.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tailwind-extension-kit (npm). Pin to a known-safe version or switch to an alternative.