Malware in tailwind-core
Malware was distributed via the npm package tailwind-core. Systems with the package installed are considered fully compromised and require immediate remediation.
- Disclosed
- Last updated
- Blast radius
- Any system with the malicious tailwind-core package installed
- Ecosystems
- Attack vectors
- Affected entities
- tailwind-corenpm package
A malicious version of the npm package tailwind-core was published and distributed to users. The package contained malware that grants full control of affected systems to an outside entity.\n\nAny computer with this package installed or running should be considered fully compromised. The malware may have established persistence mechanisms that could survive package removal.\n\nImmediate action is required: all secrets, keys, and credentials stored on affected systems must be rotated from a different, uncompromised computer. The package should be removed, though removal alone may not eliminate all malicious artifacts.
Indicators of compromise
- Packages
- tailwind-core
Remediation
- Immediately remove the tailwind-core package from all affected systems
- Rotate all secrets, API keys, credentials, and tokens from a different, uncompromised computer
- Perform a full security audit and malware scan of affected systems
- Review system logs and network traffic for signs of unauthorized access or data exfiltration
- Consider the affected systems compromised and plan for full rebuild if critical infrastructure
- Monitor for any lateral movement or persistence mechanisms installed by the malware
Sources
- GitHub Advisory GHSA-m6r5-49q4-pv25 · GitHub Advisory Database
Cite this entry
"Malware in tailwind-core." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 9, 2026; last updated July 9, 2026. https://supplychainattack.org/incident/malware-in-tailwind-core-hqj244
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in typescirpt-cli (npm)
The npm package typescirpt-cli (a typosquat of typescript-cli) contained malicious code in its postinstall script that downloads and executes a binary (main.exe) on Windows and WSL systems, and exfiltrates system metadata to a hardcoded IP address.
npmTyposquattingCompromised package - containedcritical
Malicious code in typescipt-core (npm)
The npm package typescipt-core (a typosquat of typescript) contained malicious postinstall code that downloads and executes a second-stage payload on Windows and WSL systems. The dropper exfiltrates host profile information to 193.70.34.101:20099 before fetching attacker-controlled executables.
npmCompromised packageTyposquatting - containedcritical
Malicious code in typesript-cli (npm)
The npm package 'typesript-cli' (a one-character typosquat of 'typescript') contains malicious code in its postinstall script that downloads and executes a Windows PE binary, and can cross the Linux/WSL sandbox boundary to execute payloads on the Windows host. The script also beacons to a hardcoded IP endpoint.
npmTyposquattingCompromised package - resolvedcritical
Malicious code in @mohamed_nowisar/depconf-canary-test (npm)
The npm package @mohamed_nowisar/depconf-canary-test contained malicious code in its preinstall hook that automatically collected and exfiltrated host and CI environment information to an attacker-controlled webhook endpoint without user consent.
npmCompromised package