LWA-2026-12001 MAL-2026-16139 ↗ confirmed malware

tailwind-form-kit@0.6.2

Malicious code in tailwind-form-kit (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071 · Application Layer ProtocolT1102 · Web ServiceT1027 · Obfuscated Files or InformationT1070 · Indicator Removal

Analysis

tailwind-form-kit@0.6.2 is a trojanized clone of the Tailwind CSS forms plugin. Its main module src/index.js is obfuscated and, when imported, scans the Ethereum blockchain via public RPC endpoints for transactions from a hardcoded sender address, decodes the recipient address of that transaction into IP addresses, and fetches second-stage payloads from HTTP URLs built from those IPs. The fetched payloads are XOR-decoded, executed with eval, and also run in detached `node -e` child processes. The module then rewrites its own source file to strip the obfuscated prefix. The C2 endpoints are derived from the recipient address of the hardcoded sender's on-chain transaction.

analyzed by
Leitwacht
first seen
Sep 10, 2026, 06:07 PM
analyzed
Sep 10, 2026, 06:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.