Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in tailwindcss-scrollbar-hide (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 09:15:51 UTC)
Source: GCVE Database
Product: tailwindcss-scrollbar-hide

Description

The npm package tailwindcss-scrollbar-hide contains malicious code that executes an obfuscated payload upon import or require. This payload queries Ethereum public RPC endpoints and a blockchain explorer to retrieve attacker-controlled data, which it uses to dynamically fetch and execute further malicious code on the infected machine. The package masquerades as a zero-dependency CSS plugin but includes network communication, process spawning, and dynamic code execution with no legitimate purpose. Installing or running this package results in full system compromise, and secrets or keys on the affected machine should be considered exposed.

Affected software

npmghsa
tailwindcss-scrollbar-hide
Affected versions
=2.2.6=2.3.0=2.2.5=0.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 18:37:49 UTC

Technical Analysis

The tailwindcss-scrollbar-hide npm package versions 0.0.1, 2.2.5, 2.2.6, and 2.3.0 include malicious code in dist/index.js that appends an eval(atob('...')) payload after the legitimate CSS plugin export. This payload is obfuscated using Unicode escapes and, when decoded, performs blockchain queries to Ethereum public RPC endpoints and eth.blockscout.com to retrieve the latest transaction from an attacker-controlled address. It extracts two IPv4 addresses from the transaction data, fetches second-stage payloads from these IPs over HTTP, XOR-decodes them, and executes them via eval and a detached Node.js process. This mechanism allows the attacker to dynamically rotate command and control endpoints via on-chain transactions. The package's advertised function as a pure CSS plugin is a facade for this malicious behavior. The compromise is severe, as the attacker gains full control of the infected system.

Potential Impact

Any system that installs or runs the affected versions of tailwindcss-scrollbar-hide is fully compromised. The attacker can execute arbitrary code remotely, potentially leading to theft of secrets, credentials, and keys stored on the machine. The dynamic retrieval and execution of payloads from attacker-controlled infrastructure means the attacker can maintain persistent and evolving control. Removal of the package does not guarantee eradication of all malicious artifacts or backdoors, as the attacker may have established additional footholds.

Defensive Guidance

Remove the affected versions of tailwindcss-scrollbar-hide immediately. Rotate all secrets, keys, and credentials that were stored or used on the compromised system, using a different, trusted machine. Because the attacker gains full control, assume the system is fully compromised and consider rebuilding or isolating it. There is no known patch or fixed version; avoid using this package entirely. Monitor for any suspicious activity related to this package and its dependencies.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12224
Osv Schema Version
1.7.4
Aliases
["GHSA-6r49-6vv4-wpp3"]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a74cf8ebf8831d5391ae9e1

Added to database: 08/06/2026, 18:16:46 UTC

Last enriched: 08/06/2026, 18:37:49 UTC

Last updated: 08/06/2026, 18:37:49 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses