Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

tailwind-form-kitnpm

tailwind-form-kit is a confirmed malicious npm package (MAL-2026-16139) that opens a backdoor for remote access (malicious version 0.6.4). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in tailwind-form-kit (npm)

MAL-2026-16139
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall tailwind-form-kit

What this malware does

[email protected] impersonates @tailwindcss/forms (package.json sets repository to https://github.com/tailwindlabs/tailwindcss-forms) but src/index.js is a heavily obfuscated single-line loader (obfuscator.io string-array shape, all identifiers _0xNNNN). On require() — as would happen when the package is referenced from tailwind.config — the loader opens HTTP/HTTPS to Ethereum public RPCs (publicnode, drpc.org/eth, blockscout) and an Etherscan-like indexer at *stapi.io, queries a hardcoded sender address 0xa322E5f39aDC2490EfD311D3080e6f0121063e1a via eth_blockNumber / eth_getBlockByNumber / eth_getTransactionCount, extracts a base64/gzip/deflate/br-encoded payload from an x-payload-B64 header or transaction data, and invokes child_process.spawn('node',...) on the retrieved bytes. This is the EtherHiding fetch-and-exec pattern: the on-chain address acts as a mutable C2 pointer, and any developer or build machine that requires this package runs whatever code the attacker currently points it at. A CSS forms plugin has no legitimate reason to talk to Ethereum RPCs or spawn node on fetched bytes.

Malicious versions

1 flagged
0.6.4

Indicators of compromise (SHA-256)

cccb2aed2f968e146b433d2a2600f17104f0dcacfd951190771f8e59aee3a252

Detection & response playbook

Backdoor / remote access
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for tailwind-form-kit (version 0.6.4). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging tailwind-form-kit across your stack and pipelines.

  2. If you installed it — respond

    tailwind-form-kit establishes remote access, so treat any host that installed it as fully compromised. Isolate the machine, remove the package, rotate all credentials it could reach, and rebuild from a trusted image rather than cleaning in place — a backdoor may have planted additional persistence.

  3. Did it already run?

    If tailwind-form-kit was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks tailwind-form-kit before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. tailwind-form-kit on npm has been identified as a malicious package (version 0.6.4 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-020011

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks tailwind-form-kit-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the C2 callback and severs the channel.

Explore

tailwind-form-kit (npm) malicious package — MAL-2026-16139 | O3 Security