tailwind-forms-kit@0.5.3
Malicious code in tailwind-forms-kit (npm)
Analysis
tailwind-forms-kit@0.5.3 is a trojanized clone of the Tailwind CSS forms plugin. src/index.js begins with a base64 blob that is decoded and passed to eval() before the legitimate plugin code runs. The decoded payload is a Node.js loader that resolves its command-and-control infrastructure through the Ethereum blockchain: it queries public JSON-RPC endpoints (hxxps://1rpc[.]io/eth, hxxps://eth[.]drpc[.]org, hxxps://ethereum-rpc[.]publicnode[.]com, hxxps://eth-mainnet[.]public[.]blastapi[.]io, plus process.env.ETH_RPC_URL) and the Blockscout indexer (hxxps://eth[.]blockscout[.]com/api) for transactions sent by address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, then decodes the transaction's `to` field into two IPv4 addresses that act as rotating C2 hosts. It fetches second-stage JavaScript over HTTP from hxxp://<ip>:443/0x/cls and hxxp://<ip>:443/0x/ls, XOR-decodes the response body (or an x-payload-b64 response header) using the keys 'q4FZixX{!h,Sr3=@' and 'y-p_>d$0B&@^1aQk', and executes it either via eval() or by spawning a detached, stdio-ignored `node -e` child process. Requests are disguised with a Chrome 131 User-Agent and a Sec-V header carrying a campaign counter, and the loader tags the host with global.i='A10-new_npm'. Installing or requiring the package hands arbitrary remote code execution to an operator-controlled blockchain dead-drop.
- analyzed by
- Leitwacht
- first seen
- Oct 6, 2026, 08:08 AM
- analyzed
- Oct 6, 2026, 08:24 AM
- weekly installs
- 141
Related advisories
- dolyame-ui-progresscircle@35.8.1
- dolyame-boxy-desktop-bnpl-header@35.8.8
- dolyame-boxy-atom-bnpl-dangerously-html@35.5.4
- devplatform-select-fields@35.2.6
- devplatform-ui-kit@35.6.2
- tinkoff-pwa-confac-types@20.7.7
- tinkoff-fb-app-frame-page-height-dippy@20.8.4
- @subql/common@5.8.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.