tailwindcss-form-ui@0.5.1
Malicious code in tailwindcss-form-ui (npm)
Analysis
tailwindcss-form-ui@0.5.1 is a combosquat of the tailwindcss-forms plugin that ships a heavily obfuscated Ethereum blockchain scanner in src/index.js (the package's main entry, executed on require). The obfuscated code queries public Ethereum RPC endpoints (hxxps://1rpc[.]io/eth, hxxps://eth-mainnet[.]publicnode[.]com, hxxps://eth[.]drpc[.]org, plus the ETH_RPC_URL env var) and an indexer API, using eth_getBlockByNumber, eth_getTransactionCount and eth_getTransactionByHash to scan blockchain blocks for transactions sent from a hardcoded attacker-controlled address (0xa322E5f3...). It decodes Ethereum addresses into dotted-quad IP form and spawns child processes, forming a wallet-drainer / transaction-scanner implant that identifies and targets wallets that interacted with the attacker's address.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 02:06 PM
- analyzed
- Sep 17, 2026, 02:07 PM
Related advisories
- @vitemirrorte/element-plus-vite-cli@2.9.1
- tailwindcss-contact-form@0.5.1
- ragacateslikodi@1.0.1
- strapi-plugin-osag@3.6.8
- strapi-plugin-os-rec@3.6.8
- confx1789550882@1.0.0
- element-plus-vite-cli@2.9.3
- @asenfotech/unplugin-element-plus@2.9.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.