LWA-2026-12195 MAL-2026-16251 ↗ confirmed malware

tailwindcss-contact-form@0.5.1

Malicious code in tailwindcss-contact-form (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1552.001 · Credentials In FilesT1041 · Exfiltration Over C2 Channel

Analysis

tailwindcss-contact-form@0.5.1 is a trojanized clone of the legitimate tailwindcss-forms plugin. The package's main entry src/index.js is replaced with a heavily obfuscated payload (javascript-obfuscator) that runs when the module is imported. The payload builds an Ethereum JSON-RPC client that queries public RPC endpoints (h[.]drpc[.]org, publicnode, blocksco, 1rpc[.]io, ethereum-rpc, and the ETH_RPC_URL env var) and implements transaction-locating logic (eth_getBlockByNumber, eth_getTransactionCount, eth_getTransactionByHash, findSenderTx, nonceAtBlocks, lastSenderTx) targeting a hardcoded sender address 0xa322E5f3..., consistent with a wallet-drainer / transaction-frontrunning implant. It also constructs an indexer URL with Etherscan-style query parameters (module=account, action=txlist, address=, startblock, endblock, page, offset, sort=desc) and imports child_process spawn. The payload further contains npm-token-harvesting global pollution: it assigns masked npm-token markers (A10-***npm) and captures require/module via global variables (_t_u, _t_s, _H, _H2, global['r'], global['m']) to enable self-propagation, and uses x-payload- HTTP headers with XOR-encoded payload fragments.

analyzed by
Leitwacht
first seen
Sep 16, 2026, 11:33 PM
analyzed
Sep 16, 2026, 11:35 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.