VDB
GCVE-110-OSM-2026-13257
GCVE-110-OSM-2026-13257
Advisory PublishedCVSS 9.6/10
The package name tailwindcss-forms-styles mimics the legitimate @tailwindcss/forms plugin, and its src/index.js copies that plugin's code verbatim as cover. Above the cover code, a top-level IIFE joins a ~140-element base64 string array, atob()-decodes it, and eval()s the result. The decoded loader queries public Ethereum RPC/Blockscout endpoints for the most recent transaction sent by hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, parses two IPv4 addresses out of the transaction recipient field, downloads an XOR-encoded JavaScript payload from staging URLs of the form http://<ip>:443/0x/cls and http://<ip>:443/0x/ls, and executes it via eval and a detached spawn('node', ['-e',...]) child process. Because the IIFE runs at module load, any consumer that performs require('tailwindcss-forms-styles') triggers remote code execution on the installer, with the command-and-control endpoint resolved dynamically from the blockchain so the C2 can be rotated without changing the package.
ENTRY
src/index.js (main: src/index.js)
OBFUSCATION
- Decoded Base64 Content in src/index.js (x123)
- Decoded Base64 Content in [deobfuscated] src/index.js (x123)
- Dynamic Base64 Decoding in src/index.js: "atob(_0x977e9ea)"
- Obfuscation (osm-deobfuscator): unknown in src/index.js
- Strings Extracted from Deobfuscated Code in src/index.js
- recovered 6 urls, 3 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Dynamic Code Execution in scripts/release-channel.js: "exec(version)"
PAYLOAD FILES
src/index.js (+ [deobfuscated] src/index.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tailwindcss-forms-styles | all (affected) | — |
Aliases
Browse GCVE Records
3,130 records in the GCVE database · Updated October 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.