Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

tailwind-scrollbar-hidernpm

Advisory published Updated

tailwind-scrollbar-hider is a confirmed malicious npm package (MAL-2026-14512) that steals credentials and exfiltrates sensitive data (malicious versions 0.0.1, 5.0.1, 5.0.2). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in tailwind-scrollbar-hider (npm)

MAL-2026-14512
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall tailwind-scrollbar-hider

What this malware does

dist/index.js exports a small legitimate scrollbarHide Tailwind plugin and then executes eval(atob('<~39KB base64>')) at module top level, so the payload runs on any require()/import of the package. The decoded body is packed with an obfuscator.io-style string-array dispatcher (_0x355e / _0x12f0 with shuffling) that hides all string literals, and it dynamically resolves node:http, node:https, node:zlib, and child_process.spawn via createRequire(import.meta.url). At runtime it assembles an Ethereum RPC endpoint list from process.env.ETH_RPC_URL plus hardcoded providers including *.publicnode.com and h.drpc.org, together with an indexer URL and a hardcoded SENDER Ethereum address, and issues eth_blockNumber and block-range requests — the shape of an on-chain wallet-monitoring / drainer relay embedded in a CSS-only utility. A Tailwind scrollbar-hiding plugin has no legitimate need to eval a base64 blob, spawn child processes, open network sockets, or scan Ethereum blocks on import.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

3 flagged
0.0.15.0.15.0.2

Indicators of compromise (SHA-256)

419e7970b5bc0bd5afe8a044ba0c64352a634818d5a96f850657ff8506af5677
aaa2dba899c9723740dfcc2fe8588bcf695f021442bbe8de1156239029bf7987
483d9e78834043e3a66523d2a7bb8231ca6e9ed6a61b81583fef944f45bdb164
fcba8e61a7ae18004364f3e9fc0235c02ac3f19f4c836a2d444cd4a619b01b40

Detection & response playbook

Credential / info stealer
  1. Find it

    Search your lockfiles and build artifacts for tailwind-scrollbar-hider (3 malicious versions).

  2. If you installed it — respond

    tailwind-scrollbar-hider is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If tailwind-scrollbar-hider was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. tailwind-scrollbar-hider on npm has been identified as a malicious package (versions 0.0.1, 5.0.1, 5.0.2 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-869j-r989-xpvrIN-MAL-2026-018742IN-MAL-2026-019216IN-MAL-2026-019217

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks tailwind-scrollbar-hider-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

tailwind-scrollbar-hider (npm) malicious package — MAL-2026-14512 | O3 Security