LWA-2026-11169 confirmed malware

tailwind-custom-templates@0.7.2

Malicious code in tailwind-custom-templates (npm)

T1059.007 · JavaScriptT1106 · Native APIT1071.001 · Web ProtocolsT1102 · Web ServiceT1552.001 · Credentials In FilesT1195.002 · Compromise Software Supply Chain

Analysis

tailwind-custom-templates@0.7.2 is a trojanized clone of the tailwindcss-forms plugin. The package's main entry src/index.js contains the genuine plugin source followed by an obfuscated payload that executes when the module is loaded. The payload is an Ethereum wallet drainer: it reads the ETH_RPC_URL environment variable, spawns child processes, and queries Ethereum RPC endpoints (h[.]drpc[.]org, publicnode, stapi[.]io, 1rpc, ethereum-rpc, pc[.]io/eth) and Etherscan API paths (?module=ac, on=txlist&, address=, count&acti, ort=desc&f, ilterby=fr, ffset=20&s, k=0&endblo, ck=9999999) using eth_getTransactionByHash, eth_getBlockByNumber and eth_blockNumber. It embeds a hardcoded Ethereum address 0xa322E5f3 as the drainer destination and spoofs a Chrome browser User-Agent on its HTTP requests.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 10:10 AM
analyzed
Aug 13, 2026, 10:12 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.