{"id":"MAL-2026-15826","summary":"Malicious code in tailwindcss-fluid-styles (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4e9b69dc0a9e6eabb685fa4be860fa456d8810c712ab300ff87023d72cf93631)\nsrc/index.js executes an eval(atob(...)) blob at top level on require(). The decoded loader queries Ethereum RPC endpoints for the latest transaction from the hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a and decodes that transaction's `to` field into two IPv4 addresses used as C2 hosts. It fetches XOR-encrypted payloads from paths /0x/cls and /0x/ls on those hosts, eval()s the first, and spawns `node -e \u003cpayload\u003e` with `{detached:true, stdio:'ignore', windowsHide:true}` and.unref() to run the second as a persistent hidden background process on the installer's host. Immediately after execution the module reads its own source, locates the eval(atob(\"Z2x...\")) region and rewrites __filename on disk to remove it, leaving a benign-looking tailwind plugin after first import. The package presents itself as a Tailwind CSS fluid-styles plugin; the attacker-controlled code, blockchain-based C2 resolution, self-erasing loader and detached implant have no relationship to that stated purpose.\n","modified":"2026-09-02T22:30:06.116290778Z","published":"2026-09-02T22:10:01Z","database_specific":{"malicious-packages-origins":[{"sha256":"4e9b69dc0a9e6eabb685fa4be860fa456d8810c712ab300ff87023d72cf93631","source":"amazon-inspector","versions":["2.0.7"],"id":"IN-MAL-2026-019354","import_time":"2026-09-02T22:16:59.161592533Z","modified_time":"2026-09-02T22:10:01Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tailwindcss-fluid-styles/v/2.0.7"}],"affected":[{"package":{"name":"tailwindcss-fluid-styles","ecosystem":"npm","purl":"pkg:npm/tailwindcss-fluid-styles"},"versions":["2.0.7"],"database_specific":{"indicators":{"evidence_files":[{"path":"src/index.js","sha256":"71787d74070ddf30632c768e6fcba1a21fea8faf5bdf5adb7c706712547af656","tlsh":"60224cb4a3c323c17f2de5422add6b4462fb2dce21b0738e8d851eda1481d93653d668"}],"package_integrity":[{"hashes":{"sha1":"a1c8a567e544f05e7c8790fadacf39cf31c81673","sha512_sri":"sha512-BMKSlBeCOQQppBDpR0z9b/ITN7d5srT8JurR2drff3DORNuOFiw0xi8fkB+UD7+/A1TNuqtMjHA4B8rnWAhbNQ=="},"filename":"tailwindcss-fluid-styles-2.0.7.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tailwindcss-fluid-styles/MAL-2026-15826.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}