LWA-2026-11653 confirmed malware

tailwindcss-form-styles@0.5.15

Malicious code in tailwindcss-form-styles (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

tailwindcss-form-styles@0.5.15 is a trojanized clone of the @tailwindcss/forms plugin. The package bundles the genuine plugin code in src/index.js but appends a large base64-encoded payload executed via eval(atob(...)). The decoded payload is an obfuscated JavaScript client that sets a global marker "A10-npm_new2", requires http/https/zlib/url/path, and issues JSON-RPC requests to Ethereum endpoints (eth_blockNumber, eth_getTransactionCount, eth_getBalance) and blockchain explorer/API hosts including h.blockseco, h[.]drpc[.]org, pc[.]io/eth, stapi[.]io, ut[.]com/api, and h-mainnet. endpoints, using gzip/deflate encoding and spawning child processes. Installing or requiring this package executes the payload, which monitors blockchain accounts and communicates with the listed RPC/explorer hosts.

analyzed by
Leitwacht
first seen
Aug 27, 2026, 09:35 AM
analyzed
Aug 27, 2026, 09:36 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.