Tailwind CSS utilities and reusable components.
Invoking the exported plugin fetches attacker-controlled JSON from a hard-coded IP address and executes its credits field as Node.js code. The payload receives process, global, Buffer, and require.
Source passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L6Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe default export fetches a payload from a hard-coded IP endpoint.
index.jsView on unpkg · L106Remote JSON field data.credits is passed directly to Function and executed.
index.jsView on unpkg · L127Remote JSON field data.credits is passed directly to Function and executed.
index.jsView on unpkg · L148The executed payload receives require, process, global, Buffer, and filesystem-relevant path context.
index.jsView on unpkg · L155README presents this as a Tailwind plugin, unrelated to remote code delivery.
README.mdView on unpkg · L1Source passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L6Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgREADME presents this as a Tailwind plugin, unrelated to remote code delivery.
README.mdView on unpkg · L1The default export fetches a payload from a hard-coded IP endpoint.
index.jsView on unpkg · L106Remote JSON field data.credits is passed directly to Function and executed.
index.jsView on unpkg · L127Remote JSON field data.credits is passed directly to Function and executed.
index.jsView on unpkg · L148The executed payload receives require, process, global, Buffer, and filesystem-relevant path context.
index.jsView on unpkg · L155