Loading npm security reports…
A configurable, namespaced Animate.css integration for Tailwind CSS
OpenSSF/OSV advisory MAL-2026-17666 confirms this npm version as malicious. animatecss-tailwind-bridge 2.0.6 was published to npm on 2026-09-13 by the account bennetwild. The package is part of a fake job interview campaign that targets developers, using the same method as the "Contagious Interview" campaign. A fake company sends a take-home coding assessment repository. The repository commits a web/.npmrc containing a plaintext npm auth token, and its tailwind.config.js loads this package...
This report applies to animatecss-tailwind-bridge@2.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .