tailwindcss-form-styles@0.5.15
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-14568
Ecosystem
npm
Summary
src/index.js re-exports the legitimate tailwindcss-forms plugin as a working cover, then appends an obfuscator.io-style _0x string-array cipher that assigns require and module to global.r and global.m and terminates with eval(atob(<~41KB base64 blob>)). The decoded blob contains outbound HTTP client code (POST with custom Content-Type, User-Agent, gzip/deflate handling) and an EVM RPC surface targeting 1rpc.io/eth, drpc.org, and Blockscout with methods like eth_blockNumber and hardcoded contract addresses, using an on-chain dead-drop pattern to retrieve the next-stage command. A campaign tag string 'A10-npm_new2' is embedded. package.json points 'repository' at tailwindlabs/tailwindcss-forms to inherit trust from the legitimate package. The eval fires as soon as any Tailwind build loads this plugin, resulting in attacker-controlled code execution in the installer's build environment (developer machines and CI runners).
Source: amazon-inspector (4bf4e5fbd59048a5ab6a5c04ad7c98e7246c9cf57363d95acc84f92d8ca883f4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.