LWA-2026-11849 MAL-2026-15925 ↗ confirmed malware

tailwind-contact-forms@0.5.12

Malicious code in tailwind-contact-forms (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1082 · System Information DiscoveryT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

tailwind-contact-forms is a combosquat of the tailwindcss-forms plugin. Its src/index.js bundles the genuine plugin code as a decoy and appends an obfuscated Ethereum drainer that executes when the module is loaded. The payload builds an Ethereum JSON-RPC client that contacts hardcoded endpoints (hxxps://1rpc[.]io/eth, hxxps://ethereum-rpc[.]publicnode[.]com, hxxps://eth-mainnet[.]public[.]blastapi[.]io, hxxps://eth[.]drpc[.]org, or the ETH_RPC_URL env var), hardcodes the attacker wallet 0xa322E5f39aDC2490EfD311D3080e6f0121063e, scans blockchain history (including the Etherscan txlist API) to derive nonce state for that address, spawns a node child process, and fakes a browser User-Agent. Installing and loading this package runs the drainer.

analyzed by
Leitwacht
first seen
Sep 3, 2026, 08:16 AM
analyzed
Sep 3, 2026, 08:17 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.