Post

HN
Hacker News

I found a malware hiding in my TailwindCSS config file

I almost closed the file without reading it. Three days later I was killing processes in production at 2am, rotating every credential I own, and staring at a git commit with my name on it that I never made. If you’ve got an active Node project, you’ll probably want to check it before you finish reading this.

This wasn’t package.json or something deep in node_modules . It was tailwind.config.js . The file you touch once, when you’re setting up the project, figuring out whether your primary color is blue-600 or blue-700 . Then you never open it again. Half of us didn’t even write ours, it got spat out by create-next-app or a starter template and we never looked twice.

I wasn’t even looking for anything wrong. I was just copying my old color tokens into a fresh tailwind.config.js file. Except the paste took a second too long. Five lines of config shouldn’t lag a clipboard. Huh? I scrolled down to see what I’d actually copied, Nothing obvious. Then I diffed it online and discovered a wall of obfuscated code hidden after hundreds of empty spaces, like someone wanted you to stop scrolling before you ever saw it.

I want to be honest about this, this was my first time looking at something like this. What followed felt like pulling a thread and watching a sweater unravel. The more I looked, the more layers I found. Every time I thought I’d found the bottom, there was another layer under it. At the end I had a confirmed infection across three of my repos, six unknown processes running quietly in production, git commits with my own name on them that i never wrote, and a payload phoning home to api.trongrid.io , a known DPRK command and control channel.

I’m still a little shaken, reading more about this type of attack and more so because I think a lot of you have this exact file sitting open in a tab right now, unread, un-audited, completely trusted. So before anything else —

Before you keep reading, If you’ve got Node running anywhere right now — a side project, something half-abandoned, a Next.js / ReactJs app you haven’t touched in months — it might be worth pulling up a terminal and running ps aux | grep node . Just see what's there. Some of it you'll recognize immediately. Some of it might make you pause. Either way, keep that in the back of your mind, because we're coming back to it.