VDB

GCVE-110-OSM-2026-9229

GCVE-110-OSM-2026-9229
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 28, 2026
This package is a trojanized tailwindcss plugin employing a sophisticated blockchain-based C2 mechanism. The legitimate plugin code in `src/index.js` is followed by a hidden payload concealed after 97+ tab characters (whitespace-padded payload technique). The hidden payload reads from a hardcoded Ethereum address `0xa322e5f3d311d3080e6f0121063e9adc2490ef1a` via multiple RPC endpoints and blockscout API, decodes the `tx.to` field of the latest outbound transaction as two raw IPv4 addresses (8 bytes total), then fetches an XOR-encrypted second-stage payload from `http://<ip>:443/0x/ls` with a `Sec-V` authentication header, XOR-decrypts it with key `y-p_>d$0B&@^1aQk`, and `eval()`s the result — classic blockchain-steganography C2 to evade domain-based detection and takedowns. The publisher `npmuser3002` with email `fadiji3229@apdtax.com` has one package published hours ago with no repository, matching a classic typosquatting/supply-chain implant profile. The global marker `A10-npm3!` suggests an operator campaign identifier. ENTRY src/index.js (main: src/index.js) DESTINATION - reconstructed: https://eth.blockscout.com/api?module=account&action=txlist&address=0xa322e5f3d311d3080e6f0121063e9adc2490ef1a&sort=desc&filterby=from (primary, reconstructed) in src/index.js - custom-c2: eth.blockscout.com (reconstructed) in src/index.js - custom-c2: https://1rpc.io/eth (plaintext) in src/index.js - custom-c2: https://eth.drpc.org (plaintext) in src/index.js - custom-c2: https://eth.blockscout.com/api?module=account&action=txlist&address= (plaintext) in src/index.js - custom-c2: 1rpc.io (plaintext) in src/index.js - custom-c2: eth.drpc.org (plaintext) in src/index.js - ethereumAddresses: 0xa322e5f3d311d3080e6f0121063e9adc2490ef1a (exfil, plaintext) EXFIL - Network Request in src/index.js: "https.request(" OBFUSCATION - Whitespace-Padded Hidden Payload in src/index.js: "; global" - Deobfuscation Failed in src/index.js - recovered 1 urls, 1 domains from decoded/deobfuscated content ADDITIONAL FINDINGS - Reconstructed Obfuscated URL in src/index.js: "https://eth.blockscout.com/api?module=account&action=txlist&address=0xa322e5f3d3..." - Brand New Package PAYLOAD FILES src/index.js INDICATORS (IOCs) - payloadFileHash: f826e01336b1f2121fcd5a40c0d888780a250b5b0884bd4f2c57ebdf7de81d51

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownfluid-type-uiall (affected)

References

advisory
vendor

Browse GCVE Records

75,797 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›