tailwindcss-form-components@1.5.0
Malicious code in tailwindcss-form-components (npm)
Analysis
tailwindcss-form-components is a combosquat package impersonating the Tailwind CSS ecosystem. Its index.js hardcodes a C2 server at IP 46[.]183[.]25[.]232:45000 and fetches a payload from the path /icons/106. The fetched response is executed via new Function() with the full Node.js runtime context (require, process, Buffer, module, etc.) injected, giving the remote attacker arbitrary code execution on the victim's machine. The package depends on node-machine-id (host fingerprinting), better-sqlite3 and sqlite3 (local database access), socket[.]io-client (real-time C2 channel), and axios/request (HTTP exfiltration). The README links to an unrelated GitHub repository as cover.
- analyzed by
- Leitwacht
- first seen
- Jul 21, 2026, 09:07 PM
- analyzed
- Jul 21, 2026, 09:08 PM
- weekly installs
- 130
Related advisories
- chai-as-deployer@2.3.6
- chai-foundry@7.0.3
- faust-cont@1.0.0
- quickbuf@1.0.1
- app-data-ist@2.1.6
- @offa-uwk/offa-uwk@999.0.6
- code-analyzer-mcp@1.0.0
- twilio-internal@99.99.99
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.