tailwindcss-forms-styles@0.5.1
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17524
Ecosystem
npm
Summary
The package name tailwindcss-forms-styles mimics the legitimate @tailwindcss/forms plugin, and its src/index.js copies that plugin's code verbatim as cover. Above the cover code, a top-level IIFE joins a ~140-element base64 string array, atob()-decodes it, and eval()s the result. The decoded loader queries public Ethereum RPC/Blockscout endpoints for the most recent transaction sent by hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, parses two IPv4 addresses out of the transaction recipient field, downloads an XOR-encoded JavaScript payload from staging URLs of the form http://<ip>:443/0x/cls and http://<ip>:443/0x/ls, and executes it via eval and a detached spawn('node', ['-e',...]) child process. Because the IIFE runs at module load, any consumer that performs require('tailwindcss-forms-styles') triggers remote code execution on the installer, with the command-and-control endpoint resolved dynamically from the blockchain so the C2 can be rotated without changing the package.
Source: amazon-inspector (587d9a389f35a8ec2d3ed714c90f7daa43feb6875f4ce2e4280f5ce19569d895)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.