Logo
npm

tailwind-custom-forms@0.5.2

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-12221

Ecosystem

npm

Summary

The package impersonates @tailwindcss/forms: package.json declares the name tailwind-custom-forms while the repository field points at github.com/tailwindlabs/tailwindcss-forms and src/index.js contains a verbatim copy of that legitimate plugin. Appended after module.exports = forms; is eval(atob('<large base64 blob>')), which decodes and executes on any require('tailwind-custom-forms'). The decoded payload reconstructs the module names http, https, zlib, url, and child_process from \u escapes to hide its imports, uses child_process.spawn, and builds outbound HTTP requests with keep-alive agents to hosts resolved at runtime from Ethereum JSON-RPC endpoints (eth.blockscout.com/api, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) keyed off the hardcoded ETH address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, calling paths /0x/cls and /0x/ls. On-chain records act as a rotating dispatcher so the operator can update C2 hosts without republishing the package. Requiring this module executes attacker-controlled code on the installer's machine.

Source: amazon-inspector (0a94fe37df5952bc2326d9f0a759cf89d7105f47790fc71dc4731d87ec67a7f2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.