VDB
EN

MAL-2026-14038

Malicious code in tailwind-toolkit (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (afeb355b3088d1c03dbbb5a60c1afea5afbe3a384f50417ae6cfa7340d8c072d) The package presents itself as a Tailwind CSS plugin, but its default export (which runs when users register it in tailwind.config) issues an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/109 and passes the response body's `credits` field into `new Function(require, module, exports,...)` for execution in the installer's Node process. The destination URL is assembled from split variables and disguised with CDN/icon vocabulary (an unused `iconDomain` map referencing cloudflare/fastly/akamai, a `bearrtoken: "logo"` header, a response field named `credits`), while the actual host is an unrelated bare IP on a non-standard port. The package also declares dependencies on @primno/dpapi (Windows DPAPI credential decryption), better-sqlite3/sqlite3 (browser cookie and Login Data databases), and node-machine-id, indicating the retrieved payload is a browser-credential stealer. The remote host and executed bytes are fully attacker-controlled and unrelated to the advertised Tailwind CSS purpose.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tailwind-toolkit

No fixed version published yet for tailwind-toolkit (npm). Pin to a known-safe version or switch to an alternative.

참고