npm

tailwind-hide-scrollbar @2.2.1

Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC

Malicious

OSV ID

MAL-2026-12116

Ecosystem

npm

Summary

dist/index.js appends an eval(atob('...')) payload after the legitimate export default scrollbarHide; line. The decoded payload queries Ethereum RPC endpoints (eth.blockscout.com/api, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) for the latest transaction from hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, interprets bytes of the to field as IPv4 addresses, HTTP GETs http://<ip>:443/0x/cls and http://<ip>:443/0x/ls , XOR-decrypts the responses, then eval s the first stage and spawn('node', ['-e', payload], {detached:true, stdio:'ignore', windowsHide:true}).unref() to run the second stage detached. Inner strings such as child_process , http , https , spawn , and User-Agent are stored as \uXXXX unicode escapes to defeat static grep, wrapped in an outer base64 blob. The payload fires when any consumer imports the package, granting full Node-level remote code execution on the installer's host; the on-chain C2 resolution (EtherHiding) makes the destination attacker-mutable and resistant to takedowns.

Source: amazon-inspector (cb0348430af0110be6ac537a38b5bb98983ec6b6f8f1474778ff16e4a4f4e8d8)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.