LWA-2026-12212 MAL-2026-16263 ↗ confirmed malware

tailwindcss-form-utils@0.5.1

Malicious code in tailwindcss-form-utils (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web ProtocolsT1102 · Web ServiceT1082 · System Information Discovery

Analysis

tailwindcss-form-utils@0.5.1 is a combosquat of the legitimate tailwindcss-forms plugin. Its main module src/index.js is a heavily obfuscated Ethereum drainer that executes when the package is imported. It connects to Ethereum RPC endpoints (drpc[.]org, 1rpc[.]io/eth, publicnode, ethereum-rpc) and to an indexer API at hxxps://etut[.]com/api (Etherscan-style: ?module=account&action=txlist&address=...&startblock=0&endblock=9999999), scans the blockchain for transactions from the attacker-controlled address 0xa322E5f3..., decodes embedded commands/addresses from those transactions, and spawns a child node process to carry them out. Outbound traffic is masked with browser user-agent strings.

analyzed by
Leitwacht
first seen
Sep 17, 2026, 03:35 PM
analyzed
Sep 17, 2026, 03:37 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.