tailwind-custom-templates@0.7.2
Malicious code in tailwind-custom-templates (npm)
Analysis
tailwind-custom-templates@0.7.2 is a trojanized clone of the tailwindcss-forms plugin. The package's main entry src/index.js contains the genuine plugin source followed by an obfuscated payload that executes when the module is loaded. The payload is an Ethereum wallet drainer: it reads the ETH_RPC_URL environment variable, spawns child processes, and queries Ethereum RPC endpoints (h[.]drpc[.]org, publicnode, stapi[.]io, 1rpc, ethereum-rpc, pc[.]io/eth) and Etherscan API paths (?module=ac, on=txlist&, address=, count&acti, ort=desc&f, ilterby=fr, ffset=20&s, k=0&endblo, ck=9999999) using eth_getTransactionByHash, eth_getBlockByNumber and eth_blockNumber. It embeds a hardcoded Ethereum address 0xa322E5f3 as the drainer destination and spoofs a Chrome browser User-Agent on its HTTP requests.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 10:10 AM
- analyzed
- Aug 13, 2026, 10:12 AM
Related advisories
- bnpl-blocks-mobile-bnpl-faq@35.5.3
- dolyame-ui-filter@35.5.3
- devplatform-spa-plugin-notifier@35.5.7
- beaver-ui-actions-button@5.4.7
- snavbox@1.0.1
- try-lock-runner@3.2.1
- single-flight-lock@1.0.0
- priority-mutex-lane@2.5.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.