MAL-2026-10550
Dashboard / Malicious Package / MAL-2026-10550
MAL-2026-10550
Summary: Malicious code in better-tailwindcss (npm)
Details: Source: amazon-inspector (302c3b7766a431cefe81d41434fd4c5aae74aacec230488bd004eca18cbe8dff) The package publishes under the name of the legitimate `better-tailwindcss` project but its package.json declares both a runtime and dev dependency on `better-tailwindcss` resolved from `http://pack.nppacks.com/npm/better-tailwindcss` — a plain-HTTP, non-registry host with no integrity hash and no TLS. On `npm install`, npm fetches and installs that arbitrary, mutable tarball, and any install/postinstall scripts inside it execute on the installer's machine. The shipped code itself is a Babel plugin clone unrelated to the real better-tailwindcss project (a tailwind ESLint plugin) and carries a self-label describing the package as being for 'Security Research Testing Purpose,' confirming it is a namespace squat used as a delivery vehicle for code hosted at pack.nppacks.com.
References: https://www.npmjs.com/package/better-tailwindcss/v/4.6.3, https://github.com/advisories/GHSA-w8pj-3w7c-464w
Affected packages
Package
Name: better-tailwindcss
Purl: pkg:npm/better-tailwindcss
Affected ranges
Type: N/A
Events:
