tailwindcss-contact-forms@0.5.8
Malicious code in tailwindcss-contact-forms (npm)
Analysis
tailwindcss-contact-forms is a trojanized clone of the legitimate @tailwindcss/forms plugin. The package's main entry src/index.js ships the real plugin code but appends an obfuscated implant that runs when the module is loaded. The implant queries Ethereum mainnet RPC endpoints to locate a specific sender's latest on-chain transaction, decodes the transaction recipient address into a C2 host:port, then connects to that host over HTTP and fetches a payload that it XOR-decodes and base64-decodes before executing. The C2 endpoint is thus hidden inside an on-chain transaction rather than in the package itself. The implant also imports child_process spawn and maintains keep-alive HTTP/HTTPS connection pools for the C2 channel.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 12:48 PM
- analyzed
- Sep 10, 2026, 12:49 PM
Related advisories
- @staticj/cropperjs@1.6.0
- tailwind-scrollbar-styles@4.0.3
- tailwindcss-fluid-styles@2.0.7
- bt2-api-gateway-node-js@999.0.0
- tailwindcss-3d-styles@1.2.2
- @divineubg/divine@1.1.2
- tailwind-modernanimation@2.3.8
- zenntechinc-cli@1.6.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.