OpenSSF/OSV advisory MAL-2026-16405 confirms this npm version as malicious. The package presents itself as a Tailwind CSS forms plugin but its main entry src/index.js is heavily obfuscated (obfuscator.io-style rotated string array of 303 entries, hex-named identifiers, control-flow flattening) and has no relationship to the legitimate tailwindlabs/tailwindcss-forms project it mimics. On require()/import — which occurs whenever a consumer loads the plugin from tailwind.config — the module...
Package source references dynamic require/import behavior.
tailwind.config.jsView on unpkg · L7Source contains an obfuscated payload loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThis report applies to tailwind-form-styles@0.5.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
tailwind.config.jsView on unpkg · L7Source contains an obfuscated payload loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg