LWA-2026-12194 MAL-2026-16282 ↗ confirmed malware

tailwindcss-form@0.5.1

Malicious code in tailwindcss-form (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1027 · Obfuscated Files or Information

Analysis

tailwindcss-form is a trojanized clone of the tailwindcss-forms plugin (name missing the 's'). Its src/index.js prepends an obfuscated dropper that runs before the plugin code. The dropper queries Ethereum RPC endpoints (eth_blockNumber, eth_getTransactionCount, eth_getBlockByNumber) to find a transaction from hardcoded sender address 0xa322E5f3..., decodes the transaction's recipient address into an IPv4 dotted-quad host, fetches a second-stage payload from hxxp://<decoded-ip>/[.][.][.], XOR-decodes it, and executes it both via eval and by spawning a detached `node -e` process. It then rewrites its own source file to remove the obfuscated payload. The C2 host is derived dynamically from the Ethereum blockchain rather than hardcoded.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 11:33 PM
analyzed
Sep 16, 2026, 11:33 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.