LWA-2026-12203 MAL-2026-16262 ↗ confirmed malware

tailwindcss-form-ui@0.5.1

Malicious code in tailwindcss-form-ui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1041 · Exfiltration Over C2 Channel

Analysis

tailwindcss-form-ui@0.5.1 is a combosquat of the tailwindcss-forms plugin that ships a heavily obfuscated Ethereum blockchain scanner in src/index.js (the package's main entry, executed on require). The obfuscated code queries public Ethereum RPC endpoints (hxxps://1rpc[.]io/eth, hxxps://eth-mainnet[.]publicnode[.]com, hxxps://eth[.]drpc[.]org, plus the ETH_RPC_URL env var) and an indexer API, using eth_getBlockByNumber, eth_getTransactionCount and eth_getTransactionByHash to scan blockchain blocks for transactions sent from a hardcoded attacker-controlled address (0xa322E5f3...). It decodes Ethereum addresses into dotted-quad IP form and spawns child processes, forming a wallet-drainer / transaction-scanner implant that identifies and targets wallets that interacted with the attacker's address.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 02:06 PM
analyzed
Sep 17, 2026, 02:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.