tailwind-form-styles@0.5.1
Malicious code in tailwind-form-styles (npm)
Analysis
tailwind-form-styles@0.5.1 is a trojanized clone of the @tailwindcss/forms plugin. Its main entry (src/index.js) is obfuscated and, when the module is loaded, runs an Ethereum-based command-and-control implant. It queries public Ethereum RPC endpoints (eth-mainnet[.]publicnode[.]com, eth[.]drpc[.]org, 1rpc[.]io) and a blockscout indexer to locate the latest transaction from a hardcoded sender address (0xa322E5f3...), then decodes the transaction's recipient field into an IP address that becomes the C2 host. It fetches a payload from that host over HTTP, XOR-decodes it, and executes it both via eval and by spawning a detached `node -e` process, enabling remote code execution. After running, the file rewrites itself to strip the obfuscated payload block, leaving only the benign-looking tailwind plugin code.
- analyzed by
- Leitwacht
- first seen
- Sep 18, 2026, 06:18 PM
- analyzed
- Sep 18, 2026, 06:18 PM
Related advisories
- kamafhbnowct@1.0.0
- @biz44/id95-client@1.1.96
- @biz44/id12-client@1.1.13
- greensaver@1.2.2
- gas-price-checker@1.0.0
- tailwind-container-queries@0.1.1
- tuxcmdfhjkw@1.0.0
- xsjukcnv8low26@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.