LWA-2026-7182 MAL-2026-11136 ↗ confirmed malware

fluid-type-ui@2.0.8

Malicious code in fluid-type-ui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1573 · Encrypted ChannelT1105 · Ingress Tool Transfer

Analysis

Combosquat trojanized clone of the legitimate tailwindcss-fluid-type package. The package's src/index.js contains an injected payload that uses a hardcoded Ethereum address to query blockchain RPC endpoints (1rpc[.]io, eth[.]drpc[.]org) for a transaction whose `to` field encodes a C2 server IP address and port. It then connects to that C2 server over HTTP, XOR-decrypts a second-stage payload, and executes it via eval. The package has no repository and no install scripts — the payload runs when the module is required.

analyzed by
Leitwacht
first seen
Jul 28, 2026, 10:25 AM
analyzed
Jul 28, 2026, 10:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.