fluid-type-ui@2.0.8
Malicious code in fluid-type-ui (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool Transfer
Analysis
Combosquat trojanized clone of the legitimate tailwindcss-fluid-type package. The package's src/index.js contains an injected payload that uses a hardcoded Ethereum address to query blockchain RPC endpoints (1rpc[.]io, eth[.]drpc[.]org) for a transaction whose `to` field encodes a C2 server IP address and port. It then connects to that C2 server over HTTP, XOR-decrypts a second-stage payload, and executes it via eval. The package has no repository and no install scripts — the payload runs when the module is required.
- analyzed by
- Leitwacht
- first seen
- Jul 28, 2026, 10:25 AM
- analyzed
- Jul 28, 2026, 10:28 AM
Related advisories
- chai-as-rendered@1.2.0
- system-performance-helper@1.0.1
- crypto-checkout-api@1.0.0
- sync-grove@1.0.1
- chai-as-hardened@7.0.9
- core-dotenv@1.4.1
- http-ws-listener@1.0.5
- chai-as-verified@7.1.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.