mal-2026-15925

ossf_malicious_packages
Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (6d82b6065d9e3d4a4ebba479ed42deb342f72c48d2d69d297f3926c0225828aa) The package's main module src/index.js begins with eval(atob("...")) that decodes ~30 KB of obfuscated JavaScript before the genuine plugin code. The decoded loader imports http/https/zlib and child_process.spawn, hoists require and module onto globals (global['r'], global['m']) to escape the module sandbox, and evaluates payloads received from remote endpoints. The loader hardcodes an Ethereum sender address (assembled from fragments including '0xa322E5f3','D311D3080e','6f0121063e') and a set of RPC endpoints on public Ethereum nodes (drpc.org, publicnode.com, blockscout, ethereum-rpc) plus an Etherscan-style indexer queried with 'module=account&action=txlist&address=...&sort=desc'. It polls eth_blockNumber / eth_getBlockByNumber / eth_getTransactionCount to monitor the on-chain address and retrieves payloads carried in x-payload-b64 headers, decompressed through zlib createGunzip/createInflate and executed. The loader fires on any require('tailwind-contact-forms'). The package name mimics @tailwindcss/forms and its package.json repository field points at https://github.com/tailwindlabs/tailwindcss-forms; the obfuscated loader is prepended above a verbatim copy of the legitimate @tailwindcss/forms plugin source so the package appears to work normally after infection.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          },
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "src/index.js",
              "sha256": "901605dc8863d7b3ad4b767d27847881c70a6d9ccb96dc6f3e2a40db779bfb02",
              "tlsh": "b103c906bac13571234b5f7b760bf4e4e02e2d9d7698048bd129bc94f961329d8e2b39"
            },
            {
              "path": "package.json",
              "sha256": "5c99aaa1c44832939389b4f27a7b10aec4d559021aab7d02d031fe80ea536e6d",
              "tlsh": "dc21cb26cd140e7701e0693696f911837297a463895cfc193396c19c8f8d6bfe0f909f"
            }
          ],
          "package_integrity": [
            {
              "filename": "tailwind-contact-forms-0.5.12.tgz",
              "hashes": {
                "sha1": "dfd4597f50aaab8541f224eea73f4adb8be386d4",
                "sha512_sri": "sha512-RfKyVBSVuj9Z8lmXNd6W3GDsPWyHRONhWLLxnVN40JwVbsik7EUvftW8FVV938YdtpDWolC3vQqzc9zP2IDDiA=="
              }
            }
          ]
        }
      },
      "package": {
        "ecosystem": "npm",
        "name": "tailwind-contact-forms"
      },
      "versions": [
        "0.5.12",
        "0.5.1"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "malicious-packages-origins": [
      {
        "id": "IN-MAL-2026-019640",
        "import_time": "2026-09-04T06:53:31.795019554Z",
        "modified_time": "2026-09-04T06:48:54Z",
        "sha256": "0ec029f2c6cc211c953394dfe89a4ba0921f1a526ca2b0235672f6fdeca10c50",
        "source": "amazon-inspector",
        "versions": [
          "0.5.12"
        ]
      },
      {
        "id": "IN-MAL-2026-020492",
        "import_time": "2026-09-23T14:19:31.892811335Z",
        "modified_time": "2026-09-23T14:10:59Z",
        "sha256": "6d82b6065d9e3d4a4ebba479ed42deb342f72c48d2d69d297f3926c0225828aa",
        "source": "amazon-inspector",
        "versions": [
          "0.5.1"
        ]
      }
    ]
  },
  "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6d82b6065d9e3d4a4ebba479ed42deb342f72c48d2d69d297f3926c0225828aa)\nThe package's main module src/index.js begins with eval(atob(\"...\")) that decodes ~30 KB of obfuscated JavaScript before the genuine plugin code. The decoded loader imports http/https/zlib and child_process.spawn, hoists require and module onto globals (global['r'], global['m']) to escape the module sandbox, and evaluates payloads received from remote endpoints. The loader hardcodes an Ethereum sender address (assembled from fragments including '0xa322E5f3','D311D3080e','6f0121063e') and a set of RPC endpoints on public Ethereum nodes (drpc.org, publicnode.com, blockscout, ethereum-rpc) plus an Etherscan-style indexer queried with 'module=account&action=txlist&address=...&sort=desc'. It polls eth_blockNumber / eth_getBlockByNumber / eth_getTransactionCount to monitor the on-chain address and retrieves payloads carried in x-payload-b64 headers, decompressed through zlib createGunzip/createInflate and executed. The loader fires on any require('tailwind-contact-forms'). The package name mimics @tailwindcss/forms and its package.json repository field points at https://github.com/tailwindlabs/tailwindcss-forms; the obfuscated loader is prepended above a verbatim copy of the legitimate @tailwindcss/forms plugin source so the package appears to work normally after infection.\n",
  "id": "MAL-2026-15925",
  "modified": "2026-09-23T14:22:02.283684027Z",
  "published": "2026-09-04T06:48:54Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/tailwind-contact-forms/v/0.5.12"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/tailwind-contact-forms/v/0.5.1"
    }
  ],
  "schema_version": "1.7.4",
  "summary": "Malicious code in tailwind-contact-forms (npm)"
}
View JSON API Download JSON