Logo
npm

tailwind-contact-forms@0.5.12

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC

Malicious

OSV ID

MAL-2026-15925

Ecosystem

npm

Summary

The package is published under a name that mimics the Tailwind CSS forms plugin and its package.json points repository at tailwindlabs/tailwindcss-forms, while the actual main entry src/index.js is a heavily obfuscated Node loader (obfuscator.io-style rotated string array _0x18ab with 303 entries, decoder _0x35ba, control-flow-object dispatch). On require(), the loader constructs an Etherscan-style indexer URL and Ethereum JSON-RPC endpoint list (eth.blockscout, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) from decoded string fragments, queries eth_blockNumber / eth_getBlockByNumber / eth_getTransactionCount and the txlist API for hardcoded attacker addresses (0xa322E5f3...9aDC2490Ef and 0x...D311D3080e...6f0121063e), and assembles a runtime code payload injected via global['_V...']/global['_t_u']/global['_t_s']/global['_H']/global['_H2']. The loader imports node:child_process.spawn to execute the retrieved payload. This is the EtherHiding pattern: the attacker updates transaction data on-chain to rotate second-stage code without republishing the package, and every consumer that loads tailwind-contact-forms in their tailwind.config.js executes whatever the attacker's on-chain transaction currently points to. A Tailwind plugin has no legitimate need for obfuscation, Ethereum RPC access, block-explorer indexers, or child_process spawning.

Source: amazon-inspector (956943b584d41e6307a8bb5bfdd821bd062f5f9f4776b912ee05ce41fe1829e5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.