Malicious code in tailwindcss-scrollbar-hide (npm)
The npm package tailwindcss-scrollbar-hide contains malicious code that executes an obfuscated payload upon import or require. This payload queries Ethereum public RPC endpoints and a blockchain explorer to retrieve attacker-controlled data, which it uses to dynamically fetch and execute further malicious code on the infected machine. The package masquerades as a zero-dependency CSS plugin but includes network communication, process spawning, and dynamic code execution with no legitimate purpose. Installing or running this package results in full system compromise, and secrets or keys on the affected machine should be considered exposed.
AI Analysis
Technical Summary
The tailwindcss-scrollbar-hide npm package versions 0.0.1, 2.2.5, 2.2.6, and 2.3.0 include malicious code in dist/index.js that appends an eval(atob('...')) payload after the legitimate CSS plugin export. This payload is obfuscated using Unicode escapes and, when decoded, performs blockchain queries to Ethereum public RPC endpoints and eth.blockscout.com to retrieve the latest transaction from an attacker-controlled address. It extracts two IPv4 addresses from the transaction data, fetches second-stage payloads from these IPs over HTTP, XOR-decodes them, and executes them via eval and a detached Node.js process. This mechanism allows the attacker to dynamically rotate command and control endpoints via on-chain transactions. The package's advertised function as a pure CSS plugin is a facade for this malicious behavior. The compromise is severe, as the attacker gains full control of the infected system.
Potential Impact
Any system that installs or runs the affected versions of tailwindcss-scrollbar-hide is fully compromised. The attacker can execute arbitrary code remotely, potentially leading to theft of secrets, credentials, and keys stored on the machine. The dynamic retrieval and execution of payloads from attacker-controlled infrastructure means the attacker can maintain persistent and evolving control. Removal of the package does not guarantee eradication of all malicious artifacts or backdoors, as the attacker may have established additional footholds.
Mitigation Recommendations
Remove the affected versions of tailwindcss-scrollbar-hide immediately. Rotate all secrets, keys, and credentials that were stored or used on the compromised system, using a different, trusted machine. Because the attacker gains full control, assume the system is fully compromised and consider rebuilding or isolating it. There is no known patch or fixed version; avoid using this package entirely. Monitor for any suspicious activity related to this package and its dependencies.
Malicious code in tailwindcss-scrollbar-hide (npm)
Description
The npm package tailwindcss-scrollbar-hide contains malicious code that executes an obfuscated payload upon import or require. This payload queries Ethereum public RPC endpoints and a blockchain explorer to retrieve attacker-controlled data, which it uses to dynamically fetch and execute further malicious code on the infected machine. The package masquerades as a zero-dependency CSS plugin but includes network communication, process spawning, and dynamic code execution with no legitimate purpose. Installing or running this package results in full system compromise, and secrets or keys on the affected machine should be considered exposed.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tailwindcss-scrollbar-hide npm package versions 0.0.1, 2.2.5, 2.2.6, and 2.3.0 include malicious code in dist/index.js that appends an eval(atob('...')) payload after the legitimate CSS plugin export. This payload is obfuscated using Unicode escapes and, when decoded, performs blockchain queries to Ethereum public RPC endpoints and eth.blockscout.com to retrieve the latest transaction from an attacker-controlled address. It extracts two IPv4 addresses from the transaction data, fetches second-stage payloads from these IPs over HTTP, XOR-decodes them, and executes them via eval and a detached Node.js process. This mechanism allows the attacker to dynamically rotate command and control endpoints via on-chain transactions. The package's advertised function as a pure CSS plugin is a facade for this malicious behavior. The compromise is severe, as the attacker gains full control of the infected system.
Potential Impact
Any system that installs or runs the affected versions of tailwindcss-scrollbar-hide is fully compromised. The attacker can execute arbitrary code remotely, potentially leading to theft of secrets, credentials, and keys stored on the machine. The dynamic retrieval and execution of payloads from attacker-controlled infrastructure means the attacker can maintain persistent and evolving control. Removal of the package does not guarantee eradication of all malicious artifacts or backdoors, as the attacker may have established additional footholds.
Defensive Guidance
Remove the affected versions of tailwindcss-scrollbar-hide immediately. Rotate all secrets, keys, and credentials that were stored or used on the compromised system, using a different, trusted machine. Because the attacker gains full control, assume the system is fully compromised and consider rebuilding or isolating it. There is no known patch or fixed version; avoid using this package entirely. Monitor for any suspicious activity related to this package and its dependencies.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12224
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-6r49-6vv4-wpp3"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a74cf8ebf8831d5391ae9e1
Added to database: 08/06/2026, 18:16:46 UTC
Last enriched: 08/06/2026, 18:37:49 UTC
Last updated: 08/06/2026, 18:37:49 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.