VDB

GCVE-110-OSM-2026-13257

GCVE-110-OSM-2026-13257
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published October 5, 2026
The package name tailwindcss-forms-styles mimics the legitimate @tailwindcss/forms plugin, and its src/index.js copies that plugin's code verbatim as cover. Above the cover code, a top-level IIFE joins a ~140-element base64 string array, atob()-decodes it, and eval()s the result. The decoded loader queries public Ethereum RPC/Blockscout endpoints for the most recent transaction sent by hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, parses two IPv4 addresses out of the transaction recipient field, downloads an XOR-encoded JavaScript payload from staging URLs of the form http://<ip>:443/0x/cls and http://<ip>:443/0x/ls, and executes it via eval and a detached spawn('node', ['-e',...]) child process. Because the IIFE runs at module load, any consumer that performs require('tailwindcss-forms-styles') triggers remote code execution on the installer, with the command-and-control endpoint resolved dynamically from the blockchain so the C2 can be rotated without changing the package. ENTRY src/index.js (main: src/index.js) OBFUSCATION - Decoded Base64 Content in src/index.js (x123) - Decoded Base64 Content in [deobfuscated] src/index.js (x123) - Dynamic Base64 Decoding in src/index.js: "atob(_0x977e9ea)" - Obfuscation (osm-deobfuscator): unknown in src/index.js - Strings Extracted from Deobfuscated Code in src/index.js - recovered 6 urls, 3 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Dynamic Code Execution in scripts/release-channel.js: "exec(version)" PAYLOAD FILES src/index.js (+ [deobfuscated] src/index.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntailwindcss-forms-stylesall (affected)—

References

advisory
vendor

Browse GCVE Records

3,130 records in the GCVE database · Updated October 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›