Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-16049 confirms this npm version as malicious. src/index.js, referenced by the package main and executed on require(), performs an HTTP GET to http://tailwindlan.online, writes the response body to a sibling file, and immediately require()s that file, giving the operator of tailwindlan.online arbitrary code execution in the installer's Node.js process at import time...
Package source references dynamic require/import behavior.
tests/test.jsView on unpkg · L1This report applies to tailwindcss-aspectratio-styles@0.3.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
tests/test.jsView on unpkg · L1