A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities.
Importing `src/index.js` decodes and evaluates obfuscated code that includes network requests and child-process capabilities. The payload also contains a dynamically constructed loader URL.
Source decodes a Base64-obscured HTTP endpoint at runtime.
src/index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round2View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/index.js#virtual:base64:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg`package.json` has no install lifecycle hook; the suspicious behavior is reached when the package entrypoint is imported.
package.jsonView on unpkg · L20This report applies to tailwind-forms-kit@0.5.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
src/index.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round2View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/index.js#virtual:base64:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg`package.json` has no install lifecycle hook; the suspicious behavior is reached when the package entrypoint is imported.
package.jsonView on unpkg · L20