{"id":"MAL-2026-16139","summary":"Malicious code in tailwind-form-kit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (92f4a69a3b50ac2347f8b3324abca2c0df1cf83422ee0f164b799cb748fa76b5)\nThe package presents itself as a Tailwind CSS forms plugin but its main entry src/index.js is a heavily obfuscated module (obfuscator.io-style rotating string array with 303 entries, hex identifiers, control-flow dispatchers) that on require/import dynamically loads node:http, node:https, node:zlib, and node:child_process via createRequire and stashes them on the global object. On module load it issues POST requests carrying a custom x-payload-* header and a spoofed Chrome/Windows User-Agent to a hardcoded blockchain indexer (etherscan/blockscout-style) and to public Ethereum RPC providers (publicnode.com, drpc.org, 1rpc.io, eth-mainnet), reading process.env.ETH_RPC_URL to augment the RPC list, and references a hardcoded Ethereum sender address. None of this behavior is disclosed and none of it corresponds to a Tailwind CSS forms plugin; the repository field also impersonates tailwindlabs. The combination of heavy obfuscation, dynamic-require caching on global, spawn availability, and unsolicited outbound blockchain network I/O at library-load is a covert import-time channel unrelated to the advertised purpose.\n\n## Source: ghsa-malware (2f393dd02d60e026717c58d23e86b376b0a47b73038607f8ddd9254442f0d1e6)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-8p5f-pjcw-69mw"],"modified":"2026-09-14T15:45:46.563524512Z","published":"2026-09-11T17:33:38Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["0.6.4"],"id":"IN-MAL-2026-020011","import_time":"2026-09-11T23:15:29.921790628Z","modified_time":"2026-09-11T22:39:48Z","sha256":"cccb2aed2f968e146b433d2a2600f17104f0dcacfd951190771f8e59aee3a252"},{"id":"GHSA-8p5f-pjcw-69mw","import_time":"2026-09-14T04:01:19.289435Z","modified_time":"2026-09-11T17:33:39Z","ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"2f393dd02d60e026717c58d23e86b376b0a47b73038607f8ddd9254442f0d1e6","source":"ghsa-malware"},{"modified_time":"2026-09-14T15:39:55Z","sha256":"92f4a69a3b50ac2347f8b3324abca2c0df1cf83422ee0f164b799cb748fa76b5","source":"amazon-inspector","versions":["0.6.2"],"id":"IN-MAL-2026-020017","import_time":"2026-09-14T15:41:10.905724359Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tailwind-form-kit/v/0.6.4"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8p5f-pjcw-69mw"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tailwind-form-kit/v/0.6.2"}],"affected":[{"package":{"name":"tailwind-form-kit","ecosystem":"npm","purl":"pkg:npm/tailwind-form-kit"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["0.6.4","0.6.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tailwind-form-kit/MAL-2026-16139.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"fd1ef3edfc6c02581abf6bf69f9e73b19ca8d3ddc915fa51beba648e6c0ae62f","tlsh":"e103e9957e81121a33434f7fba1bf4e4e12a1899369448c7d21cbc94f8e631ae9f6d34","path":"src/index.js"},{"tlsh":"df21cb22cd140e7701e0693596f9018372975463895cf8193386c19c8f8d5bfe0f909f","path":"package.json","sha256":"221ce8f5a744bf9f00995ad42340d9693932e4eba9881310127712d5c635ec32"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}