Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malware in tailwind-core

Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Any system with the malicious tailwind-core package installed
Ecosystems
Attack vectors
Affected entities
  • tailwind-corenpm package

A malicious version of the npm package tailwind-core was published and distributed to users. The package contained malware that grants full control of affected systems to an outside entity.\n\nAny computer with this package installed or running should be considered fully compromised. The malware may have established persistence mechanisms that could survive package removal.\n\nImmediate action is required: all secrets, keys, and credentials stored on affected systems must be rotated from a different, uncompromised computer. The package should be removed, though removal alone may not eliminate all malicious artifacts.

Indicators of compromise

Packages
  • tailwind-core

Remediation

  • Immediately remove the tailwind-core package from all affected systems
  • Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer
  • Perform a full security audit and malware scan of affected systems
  • Review system logs and network traffic for signs of unauthorized access or data exfiltration
  • Consider the affected systems compromised and plan for full rebuild if critical infrastructure
  • Monitor for any lateral movement or persistence mechanisms installed by the malware

Sources

  1. GitHub Advisory GHSA-m6r5-49q4-pv25 · GitHub Advisory Database

Cite this entry

"Malware in tailwind-core." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 9, 2026. https://supplychainattack.org/incident/malware-in-tailwind-core-hqj244

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in typescirpt-cli (npm)

    The npm package typescirpt-cli (a typosquat of typescript-cli) contained malicious code in its postinstall script that downloads and executes a binary (main.exe) on Windows and WSL systems, and exfiltrates system metadata to a hardcoded IP address.

    npmTyposquattingCompromised package
  2. containedcritical

    Malicious code in typescipt-core (npm)

    The npm package typescipt-core (a typosquat of typescript) contained malicious postinstall code that downloads and executes a second-stage payload on Windows and WSL systems. The dropper exfiltrates host profile information to 193.70.34.101:20099 before fetching attacker-controlled executables.

    npmCompromised packageTyposquatting
  3. containedcritical

    Malicious code in typesript-cli (npm)

    The npm package 'typesript-cli' (a one-character typosquat of 'typescript') contains malicious code in its postinstall script that downloads and executes a Windows PE binary, and can cross the Linux/WSL sandbox boundary to execute payloads on the Windows host. The script also beacons to a hardcoded IP endpoint.

    npmTyposquattingCompromised package
  4. resolvedcritical

    Malicious code in @mohamed_nowisar/depconf-canary-test (npm)

    The npm package @mohamed_nowisar/depconf-canary-test contained malicious code in its preinstall hook that automatically collected and exfiltrated host and CI environment information to an attacker-controlled webhook endpoint without user consent.

    npmCompromised package