MAL-2026-10550

    Dashboard / Malicious Package / MAL-2026-10550

    MAL-2026-10550

    Published: 14 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-w8pj-3w7c-464w

    Summary: Malicious code in better-tailwindcss (npm)

    Details: Source: amazon-inspector (302c3b7766a431cefe81d41434fd4c5aae74aacec230488bd004eca18cbe8dff) The package publishes under the name of the legitimate `better-tailwindcss` project but its package.json declares both a runtime and dev dependency on `better-tailwindcss` resolved from `http://pack.nppacks.com/npm/better-tailwindcss` — a plain-HTTP, non-registry host with no integrity hash and no TLS. On `npm install`, npm fetches and installs that arbitrary, mutable tarball, and any install/postinstall scripts inside it execute on the installer's machine. The shipped code itself is a Babel plugin clone unrelated to the real better-tailwindcss project (a tailwind ESLint plugin) and carries a self-label describing the package as being for 'Security Research Testing Purpose,' confirming it is a namespace squat used as a delivery vehicle for code hosted at pack.nppacks.com.

    Affected packages

    Package

    Name: better-tailwindcss

    Purl: pkg:npm/better-tailwindcss

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    4.6.3