OpenSSF/OSV advisory MAL-2026-16139 confirms this npm version as malicious. The package presents itself as a Tailwind CSS forms plugin but its main entry src/index.js is a heavily obfuscated module (obfuscator.io-style rotating string array with 303 entries, hex identifiers, control-flow dispatchers) that on require/import dynamically loads node:http, node:https, node:zlib, and node:child_process via createRequire and stashes them on the global object...
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThis report applies to tailwind-form-kit@0.6.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg