Logo
npm

tailwindcss-form-styles@0.5.15

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-14568

Ecosystem

npm

Summary

src/index.js re-exports the legitimate tailwindcss-forms plugin as a working cover, then appends an obfuscator.io-style _0x string-array cipher that assigns require and module to global.r and global.m and terminates with eval(atob(<~41KB base64 blob>)). The decoded blob contains outbound HTTP client code (POST with custom Content-Type, User-Agent, gzip/deflate handling) and an EVM RPC surface targeting 1rpc.io/eth, drpc.org, and Blockscout with methods like eth_blockNumber and hardcoded contract addresses, using an on-chain dead-drop pattern to retrieve the next-stage command. A campaign tag string 'A10-npm_new2' is embedded. package.json points 'repository' at tailwindlabs/tailwindcss-forms to inherit trust from the legitimate package. The eval fires as soon as any Tailwind build loads this plugin, resulting in attacker-controlled code execution in the installer's build environment (developer machines and CI runners).

Source: amazon-inspector (4bf4e5fbd59048a5ab6a5c04ad7c98e7246c9cf57363d95acc84f92d8ca883f4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.