Malicious NPM Package Caught Mimicking Material Tailwind CSS Package

Share:

A malicious NPM package has been found masquerading as the legitimate software library for Material Tailwind, once again indicating attempts on the part of threat actors to distribute malicious code in open source software repositories.

Material Tailwind is a CSS-based framework advertised by its maintainers as an “easy to use components library for Tailwind CSS and Material Design.”

“The malicious Material Tailwind npm package, while posing as a helpful development tool, has an automatic post-install script,” Karlo Zanki, security researcher at ReversingLabs, said in a report shared with The Hacker News.

This script is engineered to download a password-protected ZIP archive file that contains a Windows executable capable of running PowerShell scripts.

The now-removed rogue package, named material-tailwindcss, has been downloaded 320 times to date, all of which occurred on or after September 15, 2022.

In a tactic that’s becoming increasingly common, the threat actor appears to have taken ample care to mimic the functionality provided by the original package, while stealthily making use of a post installation script to introduce the malicious features.

This takes the form of a ZIP file retrieved from a remote server that embeds a Windows binary, which is given the name “DiagnosticsHub.exe” likely in an attempt to pass off the payload as a diagnostic utility.

Packed within the executable are Powershell code snippets responsible for command-and-control, communication, process manipulation, and establishing persistence by means of a scheduled task.

The typosquatted Material Tailwind module is the latest in a long list of attacks targeting open source software repositories like npm, PyPI, and RubyGems in recent years.

The attack also serves to highlight the software supply chain as an attack surface, which has risen in prominence owing to the cascading impact attackers can have by distributing malicious code that can wreak havoc across multiple platforms and enterprise environments in one go.

The supply chain threats have also prompted the U.S. government to publish a memo directing federal agencies to “use only software that complies with secure software development standards” and obtain “self-attestation for all third-party software.”

“Ensuring software integrity is key to protecting Federal systems from threats and vulnerabilities and reducing overall risk from cyberattacks,” the White House said last week.

https://thehackernews.com/2022/09/malicious-npm-package-caught-mimicking.html?

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:09 pm, Jul 8, 2025
weather icon 23°C
L: 22° | H: 25°
clear sky
Humidity: 38 %
Pressure: 1018 mb
Wind: 8 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 7 mph 40 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 26°°C 0.16 mm 16% 8 mph 58 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 11 mph 76 % 1024 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 8 mph 65 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 10 mph 65 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0 mm 0% 7 mph 38 % 1017 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 7 mph 35 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 20°°C 0 mm 0% 4 mph 40 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 50 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 58 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 51 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 58 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,987.25
0.49%
Ethereum(ETH)
€2,206.70
0.95%
Tether(USDT)
€0.85
0.02%
XRP(XRP)
€1.95
-1.46%
Solana(SOL)
€129.57
-0.57%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145524
0.24%
Shiba Inu(SHIB)
€0.000010
0.92%
Pepe(PEPE)
€0.000009
0.68%
Scroll to Top