VDB
GCVE-110-OSM-2026-9229
GCVE-110-OSM-2026-9229
Advisory PublishedCVSS 9.6/10
This package is a trojanized tailwindcss plugin employing a sophisticated blockchain-based C2 mechanism. The legitimate plugin code in `src/index.js` is followed by a hidden payload concealed after 97+ tab characters (whitespace-padded payload technique). The hidden payload reads from a hardcoded Ethereum address `0xa322e5f3d311d3080e6f0121063e9adc2490ef1a` via multiple RPC endpoints and blockscout API, decodes the `tx.to` field of the latest outbound transaction as two raw IPv4 addresses (8 bytes total), then fetches an XOR-encrypted second-stage payload from `http://<ip>:443/0x/ls` with a `Sec-V` authentication header, XOR-decrypts it with key `y-p_>d$0B&@^1aQk`, and `eval()`s the result — classic blockchain-steganography C2 to evade domain-based detection and takedowns. The publisher `npmuser3002` with email `fadiji3229@apdtax.com` has one package published hours ago with no repository, matching a classic typosquatting/supply-chain implant profile. The global marker `A10-npm3!` suggests an operator campaign identifier.
ENTRY
src/index.js (main: src/index.js)
DESTINATION
- reconstructed: https://eth.blockscout.com/api?module=account&action=txlist&address=0xa322e5f3d311d3080e6f0121063e9adc2490ef1a&sort=desc&filterby=from (primary, reconstructed) in src/index.js
- custom-c2: eth.blockscout.com (reconstructed) in src/index.js
- custom-c2: https://1rpc.io/eth (plaintext) in src/index.js
- custom-c2: https://eth.drpc.org (plaintext) in src/index.js
- custom-c2: https://eth.blockscout.com/api?module=account&action=txlist&address= (plaintext) in src/index.js
- custom-c2: 1rpc.io (plaintext) in src/index.js
- custom-c2: eth.drpc.org (plaintext) in src/index.js
- ethereumAddresses: 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a (exfil, plaintext)
EXFIL
- Network Request in src/index.js: "https.request("
OBFUSCATION
- Whitespace-Padded Hidden Payload in src/index.js: "; global"
- Deobfuscation Failed in src/index.js
- recovered 1 urls, 1 domains from decoded/deobfuscated content
ADDITIONAL FINDINGS
- Reconstructed Obfuscated URL in src/index.js: "https://eth.blockscout.com/api?module=account&action=txlist&address=0xa322e5f3d3..."
- Brand New Package
PAYLOAD FILES
src/index.js
INDICATORS (IOCs)
- payloadFileHash: f826e01336b1f2121fcd5a40c0d888780a250b5b0884bd4f2c57ebdf7de81d51
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | fluid-type-ui | all (affected) | — |
Aliases
Browse GCVE Records
75,797 records in the GCVE database · Updated August 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.