tailwind-custom-forms@0.5.2
Malicious code in tailwind-custom-forms (npm)
Analysis
tailwind-custom-forms@0.5.2 is a typosquat of the legitimate @tailwindcss/forms plugin. The package ships a cloned copy of the real Tailwind forms CSS code as a decoy, but appends a base64-encoded payload that executes on require(). The payload queries Ethereum JSON-RPC endpoints (1rpc[.]io, eth[.]drpc[.]org, ethereum-rpc[.]publicnode[.]com, eth-mainnet[.]public[.]blastapi[.]io) to find a specific on-chain transaction whose `to` field encodes two C2 IP addresses. It then establishes XOR-encrypted HTTP C2 channels to those IPs on ports 80 and 443, and spawns detached node processes running the beacon. It also fetches a second-stage payload from eth[.]blockscout[.]com. At runtime the package was observed making DNS queries and JSON-RPC POST requests to all four RPC endpoints, and attempting egress to eth-mainnet[.]public[.]blastapi[.]io.
- analyzed by
- Leitwacht
- first seen
- Aug 2, 2026, 04:24 PM
- analyzed
- Aug 2, 2026, 04:25 PM
Related advisories
- theta-sdk-js@1.2.14
- luludawang-kit@0.0.1
- jsf-utils@1.3.1
- @marketfront/bannerpopup@7.0.0
- autotel-edge@3.16.13
- autotel-cloudflare@2.18.16
- autotel-devtools@0.1.1
- autotel-mcp@0.1.14
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.