VDB
EN

MAL-2026-12223

Malicious code in tailwindcss-form-components (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ae9425c630e8b36b03993f6124066f178a86a285ae44e5e4590016ac575c4cac) index.js exposes getPlugin(), which performs an HTTP GET to http://46.183.25.232:45000/icons/106, parses the JSON response, and passes the `credits` field to `new Function(...)` with `require`, `module`, `process`, and `Buffer` injected — giving the remote endpoint full Node.js execution privileges on the consumer's host. The destination URL is assembled from split string fragments (protocol/separator/domain/path) and framed with icon/CDN-style naming (`iconDomain`, `bearrtoken: 'logo'`, path segment `icons/`), while a separate setDefaultModule function references a benign-looking cdnjs/font-awesome URL as a decoy. The package name typosquats the tailwindcss ecosystem, and declared dependencies include @primno/dpapi, better-sqlite3, and node-machine-id — libraries associated with Windows credential/DPAPI access, browser SQLite database reads, and host fingerprinting. The transport is plain HTTP to a bare IP with no integrity check, so the executed payload is attacker-controlled and mutable.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tailwindcss-form-components

No fixed version published yet for tailwindcss-form-components (npm). Pin to a known-safe version or switch to an alternative.

참고