tailwindcss-form-styles@0.5.15
Malicious code in tailwindcss-form-styles (npm)
Analysis
tailwindcss-form-styles@0.5.15 is a trojanized clone of the @tailwindcss/forms plugin. The package bundles the genuine plugin code in src/index.js but appends a large base64-encoded payload executed via eval(atob(...)). The decoded payload is an obfuscated JavaScript client that sets a global marker "A10-npm_new2", requires http/https/zlib/url/path, and issues JSON-RPC requests to Ethereum endpoints (eth_blockNumber, eth_getTransactionCount, eth_getBalance) and blockchain explorer/API hosts including h.blockseco, h[.]drpc[.]org, pc[.]io/eth, stapi[.]io, ut[.]com/api, and h-mainnet. endpoints, using gzip/deflate encoding and spawning child processes. Installing or requiring this package executes the payload, which monitors blockchain accounts and communicates with the listed RPC/explorer hosts.
- analyzed by
- Leitwacht
- first seen
- Aug 27, 2026, 09:35 AM
- analyzed
- Aug 27, 2026, 09:36 AM
Related advisories
- tailwindcss-3d-animate@1.2.2
- dsh-tauri-panel-extension@0.4.0
- hydration-vli-ui@1.0.0
- tsrml612@1.14.0
- chai-as-otc@1.0.5
- hydration-cls-ui@1.0.0
- auth-otp@1.0.5
- hydration-ui-dim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.