VDB
Sign up

MAL-2026-15905

Malicious code in tailwindcss-3d-styles (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6afb2de10208993a1e7511cb81a6f11806561b389673da3fa24d22598178b744) The package's main entry point fetches a JavaScript file from http://23.27.245.100:3000/index.js over plain HTTP at require time, writes the response to./inout.js in the current working directory, and require()s the resulting file — causing arbitrary code from that host to execute in the Node process of any consumer importing this package. The remaining code is a copy of the legitimate `tailwindcss-3d` library (per the manifest's repository/homepage), and the published name `tailwindcss-3d-styles` differs from the upstream `tailwindcss-3d`, using the upstream library as cover for the appended dropper.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tailwindcss-3d-styles

No fixed version published yet for tailwindcss-3d-styles (npm). Pin to a known-safe version or switch to an alternative.

References