Skip to main content

Malicious code in fluid-type-ui (npm)

0
Critical
Published: 07/28/2026 (07/28/2026, 13:28:21 UTC)
Source: GCVE Database
Product: fluid-type-ui

Description

The fluid-type-ui npm package version 2.0.8 contains hidden malicious code that executes arbitrary attacker-controlled commands when the package is required. This code fetches data from Ethereum JSON-RPC endpoints, decrypts it, and evaluates it, enabling persistent and dynamic command-and-control. The package masquerades as a Tailwind plugin but includes unrelated malicious functionality. Any system with this package installed should be considered fully compromised.

Affected software

npmghsa
fluid-type-ui
Affected versions
=2.0.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 00:51:50 UTC

Technical Analysis

The fluid-type-ui package at version 2.0.8 includes a concealed code block hidden by a long sequence of tab characters in src/index.js. Upon requiring the module, this code queries specific Ethereum JSON-RPC endpoints for a transaction from a hardcoded Ethereum address. It extracts two IPv4 addresses from the transaction's 'to' field, performs an HTTP GET request to the first address, XOR-decrypts the response with a 16-byte key, and evaluates the decrypted code in a context that exposes require and module objects globally. This mechanism allows the attacker to execute arbitrary code on any system loading the package, with the command-and-control server address dynamically controlled via new blockchain transactions, making takedown difficult. The malicious behavior is unrelated to the package's stated purpose as a Tailwind plugin.

Potential Impact

Systems with fluid-type-ui version 2.0.8 installed and loaded are subject to arbitrary remote code execution controlled by an attacker. This results in full system compromise, including potential theft of secrets and keys. The attacker can dynamically update the malicious payload via blockchain transactions, making the infection persistent and resistant to simple removal of the package. The compromise is severe enough that all secrets and keys on the affected system should be considered exposed and rotated immediately from a clean environment.

Mitigation Recommendations

No official patch or fix is currently available for fluid-type-ui version 2.0.8. The package should be immediately removed from all affected systems. Because the malicious code executes arbitrary commands with full control, any system that had this package installed or running should be considered fully compromised. All secrets and keys stored on the system must be rotated from a different, uncompromised machine. Monitor for any signs of persistent malicious activity and consider rebuilding affected systems from known good backups.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-11136
Osv Schema Version
1.7.4
Aliases
["GHSA-4w4v-pw3v-q85q"]
Ecosystems
["npm"]

Threat ID: 6a713368bf32cb7a347704b5

Added to database: 08/04/2026, 00:33:44 UTC

Last enriched: 08/04/2026, 00:51:50 UTC

Last updated: 09/17/2026, 21:01:26 UTC

Views: 56

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses