LWA-2026-12605 confirmed malware

tailwind-forms-kit@0.5.3

Malicious code in tailwind-forms-kit (npm)

Analysis

tailwind-forms-kit@0.5.3 is a trojanized clone of the Tailwind CSS forms plugin. src/index.js begins with a base64 blob that is decoded and passed to eval() before the legitimate plugin code runs. The decoded payload is a Node.js loader that resolves its command-and-control infrastructure through the Ethereum blockchain: it queries public JSON-RPC endpoints (hxxps://1rpc[.]io/eth, hxxps://eth[.]drpc[.]org, hxxps://ethereum-rpc[.]publicnode[.]com, hxxps://eth-mainnet[.]public[.]blastapi[.]io, plus process.env.ETH_RPC_URL) and the Blockscout indexer (hxxps://eth[.]blockscout[.]com/api) for transactions sent by address 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a, then decodes the transaction's `to` field into two IPv4 addresses that act as rotating C2 hosts. It fetches second-stage JavaScript over HTTP from hxxp://<ip>:443/0x/cls and hxxp://<ip>:443/0x/ls, XOR-decodes the response body (or an x-payload-b64 response header) using the keys 'q4FZixX{!h,Sr3=@' and 'y-p_>d$0B&@^1aQk', and executes it either via eval() or by spawning a detached, stdio-ignored `node -e` child process. Requests are disguised with a Chrome 131 User-Agent and a Sec-V header carrying a campaign counter, and the loader tags the host with global.i='A10-new_npm'. Installing or requiring the package hands arbitrary remote code execution to an operator-controlled blockchain dead-drop.

analyzed by
Leitwacht
first seen
Oct 6, 2026, 08:08 AM
analyzed
Oct 6, 2026, 08:24 AM
weekly installs
141

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.