VYPR

npm · Malicious package advisory

Malware

tailwindcss-forms-styles

MAL-2026-17524

Malicious code in tailwindcss-forms-styles (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (587d9a389f35a8ec2d3ed714c90f7daa43feb6875f4ce2e4280f5ce19569d895)
The package name tailwindcss-forms-styles mimics the legitimate @tailwindcss/forms plugin, and its src/index.js copies that plugin's code verbatim as cover. Above the cover code, a top-level IIFE joins a ~140-element base64 string array, atob()-decodes it, and eval()s the result. The decoded loader queries public Ethereum RPC/Blockscout endpoints for the most recent transaction sent by hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, parses two IPv4 addresses out of the transaction recipient field, downloads an XOR-encoded JavaScript payload from staging URLs of the form http://<ip>:443/0x/cls and http://<ip>:443/0x/ls, and executes it via eval and a detached spawn('node', ['-e',...]) child process. Because the IIFE runs at module load, any consumer that performs require('tailwindcss-forms-styles') triggers remote code execution on the installer, with the command-and-control endpoint resolved dynamically from the blockchain so the C2 can be rotated without changing the package.

Compromised versions (1)

  • 0.5.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.