LWA-2026-12247 MAL-2026-16405 ↗ confirmed malware

tailwind-form-styles@0.5.1

Malicious code in tailwind-form-styles (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1027 · Obfuscated Files or Information

Analysis

tailwind-form-styles@0.5.1 is a trojanized clone of the @tailwindcss/forms plugin. Its main entry (src/index.js) is obfuscated and, when the module is loaded, runs an Ethereum-based command-and-control implant. It queries public Ethereum RPC endpoints (eth-mainnet[.]publicnode[.]com, eth[.]drpc[.]org, 1rpc[.]io) and a blockscout indexer to locate the latest transaction from a hardcoded sender address (0xa322E5f3...), then decodes the transaction's recipient field into an IP address that becomes the C2 host. It fetches a payload from that host over HTTP, XOR-decodes it, and executes it both via eval and by spawning a detached `node -e` process, enabling remote code execution. After running, the file rewrites itself to strip the obfuscated payload block, leaving only the benign-looking tailwind plugin code.

analyzed by
Leitwacht
first seen
Sep 18, 2026, 06:18 PM
analyzed
Sep 18, 2026, 06:18 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.