tailwind-forms-styles@0.5.2
Malicious code in tailwind-forms-styles (npm)
Analysis
tailwind-forms-styles@0.5.2 is a trojanized clone of the Tailwind forms plugin. Its main module (src/index.js) is an obfuscated Ethereum front-running bot that runs when the package is required. It spawns child node processes and continuously scans Ethereum blocks via public RPC endpoints (drpc[.]org, publicnode, blocksco, stapi[.]io, 1rpc[.]io) and an etherscan-style indexer API, searching for transactions sent from a hardcoded wallet address (0xa322E5f3...) in order to race/replace them. It decodes an embedded Ethereum address into a dotted-quad IP used as a covert command-and-control destination, and carries an npm-token theft marker (A10-***npm). The package has no install hook; the malicious code executes on import.
- analyzed by
- Leitwacht
- first seen
- Sep 15, 2026, 11:59 AM
- analyzed
- Sep 15, 2026, 12:01 PM
Related advisories
- alkajsdfoiwqeusdflkjsdf@3.7.3
- n8n-nodes-sysdiag@1.0.0
- concierge-sdk@99.99.99
- hachutis@1.0.0
- hatcher-utility-dev@1.0.0
- cr-bot-common@1.0.0
- soltinel-pro@0.2.2
- gmgn-trading-kit@1.7.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.