OpenSSF/OSV advisory MAL-2026-16263 confirms this npm version as malicious. The package publishes under the name tailwindcss-form-utils while pointing its repository field at https://github.com/tailwindlabs/tailwindcss-forms and mirroring that project's README verbatim, positioning itself as a lookalike of the first-party Tailwind Labs forms plugin. Its main entrypoint src/index.js is heavily obfuscated (obfuscator.io string-array with rotation, hex identifier renaming, 303 encoded string...
Package source references dynamic require/import behavior.
tailwind.config.jsView on unpkg · L7Source contains an obfuscated payload loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkgThis report applies to tailwindcss-form-utils@0.5.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
tailwind.config.jsView on unpkg · L7Source contains an obfuscated payload loader that reconstructs and executes hidden code.
src/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-notes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/release-channel.jsView on unpkg