Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-15925 confirms this npm version as malicious. The package is published under a name that mimics the Tailwind CSS forms plugin and its package.json points repository at tailwindlabs/tailwindcss-forms, while the actual main entry src/index.js is a heavily obfuscated Node loader (obfuscator.io-style rotated string array _0x18ab with 303 entries, decoder _0x35ba, control-flow-object dispatch)...
This report applies to tailwind-contact-forms@0.5.9.
0.5.12, 0.5.1, 0.5.5, 0.5.9
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.