Malicious code in tailwind-form-kit (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cccb2aed2f968e146b433d2a2600f17104f0dcacfd951190771f8e59aee3a252) [email protected] impersonates @tailwindcss/forms (package.json sets repository to https://github.com/tailwindlabs/tailwindcss-forms) but src/index.js is a heavily obfuscated single-line loader (obfuscator.io string-array shape, all identifiers _0xNNNN). On require() — as would happen when the package is referenced from tailwind.config — the loader opens HTTP/HTTPS to Ethereum public RPCs (publicnode, drpc.org/eth, blockscout) and an Etherscan-like indexer at *stapi.io, queries a hardcoded sender address 0xa322E5f39aDC2490EfD311D3080e6f0121063e1a via eth_blockNumber / eth_getBlockByNumber / eth_getTransactionCount, extracts a base64/gzip/deflate/br-encoded payload from an x-payload-B64 header or transaction data, and invokes child_process.spawn('node',...) on the retrieved bytes. This is the EtherHiding fetch-and-exec pattern: the on-chain address acts as a mutable C2 pointer, and any developer or build machine that requires this package runs whatever code the attacker currently points it at. A CSS forms plugin has no legitimate reason to talk to Ethereum RPCs or spawn node on fetched bytes.
AI Analysis
Technical Summary
The tailwind-form-kit package version 0.6.4 is a malicious npm package impersonating the legitimate @tailwindcss/forms. Its main script is heavily obfuscated and, when loaded, connects to multiple Ethereum public RPC endpoints and a blockchain indexer to query a hardcoded Ethereum address. It retrieves encoded payloads embedded in blockchain transaction headers or data, decodes them, and executes the resulting code via child_process.spawn('node', ...). This technique, known as EtherHiding, uses the blockchain as a mutable command-and-control channel, enabling attackers to remotely control code execution on any developer or build machine that installs this package.
Potential Impact
Any developer or build system that installs or requires [email protected] will execute attacker-controlled code fetched dynamically from the Ethereum blockchain. This can lead to arbitrary code execution, compromise of build environments, theft of credentials, insertion of further malicious code, or other attacker actions. The malicious behavior is hidden behind obfuscation and masquerades as a legitimate CSS forms plugin, increasing the risk of unnoticed compromise.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove [email protected] from their projects and avoid installing or requiring this package. Verify dependencies to ensure no transitive inclusion of this malicious package. Use only trusted and verified packages from official sources. Monitor for any signs of compromise in development or build environments where this package was used. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Malicious code in tailwind-form-kit (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cccb2aed2f968e146b433d2a2600f17104f0dcacfd951190771f8e59aee3a252) [email protected] impersonates @tailwindcss/forms (package.json sets repository to https://github.com/tailwindlabs/tailwindcss-forms) but src/index.js is a heavily obfuscated single-line loader (obfuscator.io string-array shape, all identifiers _0xNNNN). On require() — as would happen when the package is referenced from tailwind.config — the loader opens HTTP/HTTPS to Ethereum public RPCs (publicnode, drpc.org/eth, blockscout) and an Etherscan-like indexer at *stapi.io, queries a hardcoded sender address 0xa322E5f39aDC2490EfD311D3080e6f0121063e1a via eth_blockNumber / eth_getBlockByNumber / eth_getTransactionCount, extracts a base64/gzip/deflate/br-encoded payload from an x-payload-B64 header or transaction data, and invokes child_process.spawn('node',...) on the retrieved bytes. This is the EtherHiding fetch-and-exec pattern: the on-chain address acts as a mutable C2 pointer, and any developer or build machine that requires this package runs whatever code the attacker currently points it at. A CSS forms plugin has no legitimate reason to talk to Ethereum RPCs or spawn node on fetched bytes.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tailwind-form-kit package version 0.6.4 is a malicious npm package impersonating the legitimate @tailwindcss/forms. Its main script is heavily obfuscated and, when loaded, connects to multiple Ethereum public RPC endpoints and a blockchain indexer to query a hardcoded Ethereum address. It retrieves encoded payloads embedded in blockchain transaction headers or data, decodes them, and executes the resulting code via child_process.spawn('node', ...). This technique, known as EtherHiding, uses the blockchain as a mutable command-and-control channel, enabling attackers to remotely control code execution on any developer or build machine that installs this package.
Potential Impact
Any developer or build system that installs or requires [email protected] will execute attacker-controlled code fetched dynamically from the Ethereum blockchain. This can lead to arbitrary code execution, compromise of build environments, theft of credentials, insertion of further malicious code, or other attacker actions. The malicious behavior is hidden behind obfuscation and masquerades as a legitimate CSS forms plugin, increasing the risk of unnoticed compromise.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should immediately remove [email protected] from their projects and avoid installing or requiring this package. Verify dependencies to ensure no transitive inclusion of this malicious package. Use only trusted and verified packages from official sources. Monitor for any signs of compromise in development or build environments where this package was used. Patch status is not yet confirmed — check the vendor advisory or npm security advisories for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-16139
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6aa49fe555bf5e2cf5a7d87e
Added to database: 09/12/2026, 00:42:13 UTC
Last enriched: 09/12/2026, 00:44:07 UTC
Last updated: 09/12/2026, 01:16:53 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.