OpenSSF/OSV advisory MAL-2026-15925 confirms this npm version as malicious. The package's main module src/index.js begins with eval(atob("...")) that decodes ~30 KB of obfuscated JavaScript before the genuine plugin code. The decoded loader imports http/https/zlib and child_process.spawn, hoists require and module onto globals (global['r'], global['m']) to escape the module sandbox, and evaluates payloads received from remote endpoints...
This report applies to tailwind-contact-forms@0.5.1.
0.5.12, 0.5.1, 0.5.5, 0.5.9
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.