VDB
GCVE-110-OSM-2026-9293
GCVE-110-OSM-2026-9293
Advisory PublishedCVSS 9.6/10
This package masquerades as a TailwindCSS animation utility but embeds a heavily obfuscated payload in src/index.js concealed via whitespace padding after the legitimate plugin export. The obfuscated payload, once deobfuscated, reveals Ethereum addresses (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a) used as exfil targets, fetched-payload domains recovered from deobfuscation (nC.kr, 1rpc.io, eth.drpc.org), and uses child_process.spawn alongside http/https modules — consistent with a crypto-drainer or cryptostealer attacker model that contacts Ethereum RPC endpoints. The publisher account (npmdeveloper405) has zero prior packages, no repository, and no homepage, fitting the profile of a throwaway account used for malware distribution. The combination of whitespace-padded payload concealment, deobfuscation yielding 9 IOCs including a hardcoded Ethereum address classified as exfil, and shell execution capability makes the malicious intent unambiguous.
ENTRY
src/index.js (main: src/index.js)
DESTINATION
- ethereumAddresses: 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a (exfil, plaintext)
- deobfuscated: nC.kr (fetched-payload, deobfuscated)
- deobfuscated: 1rpc.io (fetched-payload, deobfuscated)
- deobfuscated: eth.drpc.org (fetched-payload, deobfuscated)
OBFUSCATION
- IOCs Found in Deobfuscated Code in src/index.js
- Whitespace-Padded Hidden Payload in src/index.js: "; global"
- Obfuscation (osm-deobfuscator): unknown in src/index.js
- recovered 2 urls, 3 domains, 1 ethereumAddresses, 3 _domainCandidates from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Shell Command Execution in src/index.js: "require("child_process")"
PAYLOAD FILES
src/index.js
INDICATORS (IOCs)
- urls: https://tailwindcss-animationfound.com/configurator.html, https://alpinejs.dev/plugins/intersect, https://v3.tailwindcss.com/, https://tailwindcss.com/, https://1rpc.io/eth (+1 more)
- domains: tailwindcss.com, alpinejs.dev, v3.tailwindcss.com, ltd.tR
- payloadFileHash: e9d6aa5ac88bf50a35f4c12b34664075649be0183d5d1bc4dfb46b2e880ed88a
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | tailwind-animation-founder | all (affected) | — |
Browse GCVE Records
75,823 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.