VDB

GCVE-110-OSM-2026-9293

GCVE-110-OSM-2026-9293
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 29, 2026
This package masquerades as a TailwindCSS animation utility but embeds a heavily obfuscated payload in src/index.js concealed via whitespace padding after the legitimate plugin export. The obfuscated payload, once deobfuscated, reveals Ethereum addresses (0xa322e5f3d311d3080e6f0121063e9adc2490ef1a) used as exfil targets, fetched-payload domains recovered from deobfuscation (nC.kr, 1rpc.io, eth.drpc.org), and uses child_process.spawn alongside http/https modules — consistent with a crypto-drainer or cryptostealer attacker model that contacts Ethereum RPC endpoints. The publisher account (npmdeveloper405) has zero prior packages, no repository, and no homepage, fitting the profile of a throwaway account used for malware distribution. The combination of whitespace-padded payload concealment, deobfuscation yielding 9 IOCs including a hardcoded Ethereum address classified as exfil, and shell execution capability makes the malicious intent unambiguous. ENTRY src/index.js (main: src/index.js) DESTINATION - ethereumAddresses: 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a (exfil, plaintext) - deobfuscated: nC.kr (fetched-payload, deobfuscated) - deobfuscated: 1rpc.io (fetched-payload, deobfuscated) - deobfuscated: eth.drpc.org (fetched-payload, deobfuscated) OBFUSCATION - IOCs Found in Deobfuscated Code in src/index.js - Whitespace-Padded Hidden Payload in src/index.js: "; global" - Obfuscation (osm-deobfuscator): unknown in src/index.js - recovered 2 urls, 3 domains, 1 ethereumAddresses, 3 _domainCandidates from decoded/deobfuscated content ADDITIONAL FINDINGS - Shell Command Execution in src/index.js: "require("child_process")" PAYLOAD FILES src/index.js INDICATORS (IOCs) - urls: https://tailwindcss-animationfound.com/configurator.html, https://alpinejs.dev/plugins/intersect, https://v3.tailwindcss.com/, https://tailwindcss.com/, https://1rpc.io/eth (+1 more) - domains: tailwindcss.com, alpinejs.dev, v3.tailwindcss.com, ltd.tR - payloadFileHash: e9d6aa5ac88bf50a35f4c12b34664075649be0183d5d1bc4dfb46b2e880ed88a

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknowntailwind-animation-founderall (affected)

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›