tailwind-contact-forms@0.5.12
Malicious code in tailwind-contact-forms (npm)
Analysis
tailwind-contact-forms is a combosquat of the tailwindcss-forms plugin. Its src/index.js bundles the genuine plugin code as a decoy and appends an obfuscated Ethereum drainer that executes when the module is loaded. The payload builds an Ethereum JSON-RPC client that contacts hardcoded endpoints (hxxps://1rpc[.]io/eth, hxxps://ethereum-rpc[.]publicnode[.]com, hxxps://eth-mainnet[.]public[.]blastapi[.]io, hxxps://eth[.]drpc[.]org, or the ETH_RPC_URL env var), hardcodes the attacker wallet 0xa322E5f39aDC2490EfD311D3080e6f0121063e, scans blockchain history (including the Etherscan txlist API) to derive nonce state for that address, spawns a node child process, and fakes a browser User-Agent. Installing and loading this package runs the drainer.
- analyzed by
- Leitwacht
- first seen
- Sep 3, 2026, 08:16 AM
- analyzed
- Sep 3, 2026, 08:17 AM
Related advisories
- tailwind-contact-forms@0.5.9 same package
- real-router-telemetry@1.0.1
- order-package-saas@999.0.0
- bt2-api-gateway-node-js@999.0.0
- cminhouse-api-gateway-nodejs@999.0.0
- tailwind-minanimated@2.3.7
- mfaatest@1.0.0
- test__123q1@2.1.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.