tailwind-form-kit@0.6.2
Malicious code in tailwind-form-kit (npm)
Analysis
tailwind-form-kit@0.6.2 is a trojanized clone of the Tailwind CSS forms plugin. Its main module src/index.js is obfuscated and, when imported, scans the Ethereum blockchain via public RPC endpoints for transactions from a hardcoded sender address, decodes the recipient address of that transaction into IP addresses, and fetches second-stage payloads from HTTP URLs built from those IPs. The fetched payloads are XOR-decoded, executed with eval, and also run in detached `node -e` child processes. The module then rewrites its own source file to strip the obfuscated prefix. The C2 endpoints are derived from the recipient address of the hardcoded sender's on-chain transaction.
- analyzed by
- Leitwacht
- first seen
- Sep 10, 2026, 06:07 PM
- analyzed
- Sep 10, 2026, 06:09 PM
Related advisories
- cbc97b7a@1.1787999998.0
- sbman@1.0.0
- sbironman@1.0.0
- wormgpt-cli@1.0.1
- osinthell@1.9.5
- delta-time-32bb@1.0.0
- css-flow-render-shim@1.0.0
- css-reading-display-polyfill@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.