tailwindcss-form@0.5.1
Malicious code in tailwindcss-form (npm)
Analysis
tailwindcss-form is a trojanized clone of the tailwindcss-forms plugin (name missing the 's'). Its src/index.js prepends an obfuscated dropper that runs before the plugin code. The dropper queries Ethereum RPC endpoints (eth_blockNumber, eth_getTransactionCount, eth_getBlockByNumber) to find a transaction from hardcoded sender address 0xa322E5f3..., decodes the transaction's recipient address into an IPv4 dotted-quad host, fetches a second-stage payload from hxxp://<decoded-ip>/[.][.][.], XOR-decodes it, and executes it both via eval and by spawning a detached `node -e` process. It then rewrites its own source file to remove the obfuscated payload. The C2 host is derived dynamically from the Ethereum blockchain rather than hardcoded.
- analyzed by
- Leitwacht
- first seen
- Sep 16, 2026, 11:33 PM
- analyzed
- Sep 16, 2026, 11:33 PM
Related advisories
- chai-as-crack@7.0.5
- @biz44/id44-client@1.1.44
- tailwind-form-kit@0.6.2
- shaon-video-downloader@1.0.2
- node-helper@1.5.4
- date-fns-formatter@1.3.8
- tailwind-scrollbar-styles@4.0.3
- tailwind-container-queries@0.1.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.