A plugin that provides a basic reset for form styles that makes form elements easy to override with utilities.
OpenSSF/OSV advisory MAL-2026-15636 confirms this npm version as malicious. Package typosquats @tailwindcss/forms. On require('tailwindcss-forms-style'), src/index.js runs eval(atob(...)) on a base64 blob appended after module.exports. The decoded payload queries public Ethereum RPC endpoints (1rpc.io, eth.drpc.org, publicnode, blastapi, eth.blockscout.com) for the latest transaction from hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes an IP address from the...
Package source references child process execution.
src/index.js#virtual:base64:round1View on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round1View on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/index.js#virtual:normalized:round2View on unpkgPackage source references child process execution.
src/index.js#virtual:base64:round1View on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/index.js#virtual:base64:round1View on unpkg · L1Package source references a known benign dynamic code generation pattern.
src/index.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/index.js#virtual:normalized:round2View on unpkg