OpenSSF/OSV advisory MAL-2026-16262 confirms this npm version as malicious. Package name and repository field impersonate the legitimate tailwindlabs/tailwindcss-forms plugin, but the shipped main entry src/index.js is a fully obfuscated (obfuscator.io string-array) module that has nothing to do with Tailwind CSS. On module load it imports node:child_process (spawn), node:http/https, node:zlib and node:url, builds a list of Ethereum JSON-RPC endpoints (process.env.ETH_RPC_URL,...
This report applies to tailwindcss-form-ui@0.5.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.