A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities.
Loading the package main module immediately decodes and evaluates an obfuscated payload that performs network operations and can load further code.
Source decodes a Base64-obscured HTTP endpoint at runtime.
src/index.jsView on unpkg · L1src/index.js runs an encoded payload through eval during module loading.
src/index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round2View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/index.js#virtual:base64:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThis report applies to tailwind-forms-kit@0.5.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
src/index.jsView on unpkg · L1src/index.js runs an encoded payload through eval during module loading.
src/index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round2View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/index.js#virtual:base64:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg