VDB
EN

MAL-2026-12116

Malicious code in tailwind-hide-scrollbar (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cb0348430af0110be6ac537a38b5bb98983ec6b6f8f1474778ff16e4a4f4e8d8) dist/index.js appends an `eval(atob('...'))` payload after the legitimate `export default scrollbarHide;` line. The decoded payload queries Ethereum RPC endpoints (eth.blockscout.com/api, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) for the latest transaction from hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, interprets bytes of the `to` field as IPv4 addresses, HTTP GETs `http://<ip>:443/0x/cls` and `http://<ip>:443/0x/ls`, XOR-decrypts the responses, then `eval`s the first stage and `spawn('node', ['-e', payload], {detached:true, stdio:'ignore', windowsHide:true}).unref()` to run the second stage detached. Inner strings such as `child_process`, `http`, `https`, `spawn`, and User-Agent are stored as `\uXXXX` unicode escapes to defeat static grep, wrapped in an outer base64 blob. The payload fires when any consumer imports the package, granting full Node-level remote code execution on the installer's host; the on-chain C2 resolution (EtherHiding) makes the destination attacker-mutable and resistant to takedowns.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tailwind-hide-scrollbar

No fixed version published yet for tailwind-hide-scrollbar (npm). Pin to a known-safe version or switch to an alternative.

참고