OpenSSF/OSV advisory MAL-2026-13923 confirms this npm version as malicious. The package name resembles @tailwindcss/forms and its src/index.js copies the legitimate @tailwindcss/forms source, appending an `eval(atob(...))` payload that runs on require(). The decoded payload obfuscates its strings via \uXXXX escapes and dynamically requires http/https and child_process. At import time it queries Ethereum public RPCs and eth.blockscout.com/api for transactions from a hardcoded wallet...
Package source references child process execution.
src/index.js#virtual:base64:round1View on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round1View on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgPackage source references child process execution.
src/index.js#virtual:base64:round1View on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round1View on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg