tailwindcss-form-utils@0.5.1
Malicious code in tailwindcss-form-utils (npm)
Analysis
tailwindcss-form-utils@0.5.1 is a combosquat of the legitimate tailwindcss-forms plugin. Its main module src/index.js is a heavily obfuscated Ethereum drainer that executes when the package is imported. It connects to Ethereum RPC endpoints (drpc[.]org, 1rpc[.]io/eth, publicnode, ethereum-rpc) and to an indexer API at hxxps://etut[.]com/api (Etherscan-style: ?module=account&action=txlist&address=...&startblock=0&endblock=9999999), scans the blockchain for transactions from the attacker-controlled address 0xa322E5f3..., decodes embedded commands/addresses from those transactions, and spawns a child node process to carry them out. Outbound traffic is masked with browser user-agent strings.
- analyzed by
- Leitwacht
- first seen
- Sep 17, 2026, 03:35 PM
- analyzed
- Sep 17, 2026, 03:37 PM
Related advisories
- @vitemirrorte/element-plus-vite-cli@2.9.1
- n8n-nodes-sysdiag2@2.0.0
- tailwind-form-kit@0.6.2
- tailwindcss-contact-forms@0.5.8
- @staticj/cropperjs@1.6.0
- tailwind-scrollbar-styles@4.0.3
- tailwindcss-fluid-styles@2.0.7
- bt2-api-gateway-node-js@999.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.