Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16056 confirms this npm version as malicious. The package's main module (src/index.js) performs an https.get to http://23.27.245.100/index.js over plain HTTP, writes the response to./inout.js in the consumer's working directory, and immediately require()s the written file...
Package source references dynamic require/import behavior.
tests/test.jsView on unpkg · L1This report applies to tailwind-aspect-styles@0.4.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
tests/test.jsView on unpkg · L1