A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities.
Importing the package main entry executes concealed code before exporting the Tailwind form plugin. That code fetches a staged payload, executes it, launches a detached process, and removes its own loader.
Package source references dynamic require/import behavior.
tailwind.config.jsView on unpkg · L7This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThis report applies to tailwind-form-kit@0.6.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
tailwind.config.jsView on unpkg · L7This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg