Malicious code in fluid-type-ui (npm)
The fluid-type-ui npm package version 2.0.8 contains hidden malicious code that executes arbitrary attacker-controlled commands when the package is required. This code fetches data from Ethereum JSON-RPC endpoints, decrypts it, and evaluates it, enabling persistent and dynamic command-and-control. The package masquerades as a Tailwind plugin but includes unrelated malicious functionality. Any system with this package installed should be considered fully compromised.
AI Analysis
Technical Summary
The fluid-type-ui package at version 2.0.8 includes a concealed code block hidden by a long sequence of tab characters in src/index.js. Upon requiring the module, this code queries specific Ethereum JSON-RPC endpoints for a transaction from a hardcoded Ethereum address. It extracts two IPv4 addresses from the transaction's 'to' field, performs an HTTP GET request to the first address, XOR-decrypts the response with a 16-byte key, and evaluates the decrypted code in a context that exposes require and module objects globally. This mechanism allows the attacker to execute arbitrary code on any system loading the package, with the command-and-control server address dynamically controlled via new blockchain transactions, making takedown difficult. The malicious behavior is unrelated to the package's stated purpose as a Tailwind plugin.
Potential Impact
Systems with fluid-type-ui version 2.0.8 installed and loaded are subject to arbitrary remote code execution controlled by an attacker. This results in full system compromise, including potential theft of secrets and keys. The attacker can dynamically update the malicious payload via blockchain transactions, making the infection persistent and resistant to simple removal of the package. The compromise is severe enough that all secrets and keys on the affected system should be considered exposed and rotated immediately from a clean environment.
Mitigation Recommendations
No official patch or fix is currently available for fluid-type-ui version 2.0.8. The package should be immediately removed from all affected systems. Because the malicious code executes arbitrary commands with full control, any system that had this package installed or running should be considered fully compromised. All secrets and keys stored on the system must be rotated from a different, uncompromised machine. Monitor for any signs of persistent malicious activity and consider rebuilding affected systems from known good backups.
Malicious code in fluid-type-ui (npm)
Description
The fluid-type-ui npm package version 2.0.8 contains hidden malicious code that executes arbitrary attacker-controlled commands when the package is required. This code fetches data from Ethereum JSON-RPC endpoints, decrypts it, and evaluates it, enabling persistent and dynamic command-and-control. The package masquerades as a Tailwind plugin but includes unrelated malicious functionality. Any system with this package installed should be considered fully compromised.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fluid-type-ui package at version 2.0.8 includes a concealed code block hidden by a long sequence of tab characters in src/index.js. Upon requiring the module, this code queries specific Ethereum JSON-RPC endpoints for a transaction from a hardcoded Ethereum address. It extracts two IPv4 addresses from the transaction's 'to' field, performs an HTTP GET request to the first address, XOR-decrypts the response with a 16-byte key, and evaluates the decrypted code in a context that exposes require and module objects globally. This mechanism allows the attacker to execute arbitrary code on any system loading the package, with the command-and-control server address dynamically controlled via new blockchain transactions, making takedown difficult. The malicious behavior is unrelated to the package's stated purpose as a Tailwind plugin.
Potential Impact
Systems with fluid-type-ui version 2.0.8 installed and loaded are subject to arbitrary remote code execution controlled by an attacker. This results in full system compromise, including potential theft of secrets and keys. The attacker can dynamically update the malicious payload via blockchain transactions, making the infection persistent and resistant to simple removal of the package. The compromise is severe enough that all secrets and keys on the affected system should be considered exposed and rotated immediately from a clean environment.
Mitigation Recommendations
No official patch or fix is currently available for fluid-type-ui version 2.0.8. The package should be immediately removed from all affected systems. Because the malicious code executes arbitrary commands with full control, any system that had this package installed or running should be considered fully compromised. All secrets and keys stored on the system must be rotated from a different, uncompromised machine. Monitor for any signs of persistent malicious activity and consider rebuilding affected systems from known good backups.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-11136
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-4w4v-pw3v-q85q"]
- Ecosystems
- ["npm"]
Threat ID: 6a713368bf32cb7a347704b5
Added to database: 08/04/2026, 00:33:44 UTC
Last enriched: 08/04/2026, 00:51:50 UTC
Last updated: 09/17/2026, 21:01:26 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.