LWA-2026-6999 MAL-2026-12223 ↗ confirmed malware

tailwindcss-form-components@1.5.0

Malicious code in tailwindcss-form-components (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information Discovery

Analysis

tailwindcss-form-components is a combosquat package impersonating the Tailwind CSS ecosystem. Its index.js hardcodes a C2 server at IP 46[.]183[.]25[.]232:45000 and fetches a payload from the path /icons/106. The fetched response is executed via new Function() with the full Node.js runtime context (require, process, Buffer, module, etc.) injected, giving the remote attacker arbitrary code execution on the victim's machine. The package depends on node-machine-id (host fingerprinting), better-sqlite3 and sqlite3 (local database access), socket[.]io-client (real-time C2 channel), and axios/request (HTTP exfiltration). The README links to an unrelated GitHub repository as cover.

analyzed by
Leitwacht
first seen
Jul 21, 2026, 09:07 PM
analyzed
Jul 21, 2026, 09:08 PM
weekly installs
130

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.