MAL-2026-15905

    Dashboard / Malicious Package / MAL-2026-15905

    MAL-2026-15905

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in tailwindcss-3d-styles (npm)

    Details: Source: amazon-inspector (6afb2de10208993a1e7511cb81a6f11806561b389673da3fa24d22598178b744) The package's main entry point fetches a JavaScript file from http://23.27.245.100:3000/index.js over plain HTTP at require time, writes the response to./inout.js in the current working directory, and require()s the resulting file — causing arbitrary code from that host to execute in the Node process of any consumer importing this package. The remaining code is a copy of the legitimate `tailwindcss-3d` library (per the manifest's repository/homepage), and the published name `tailwindcss-3d-styles` differs from the upstream `tailwindcss-3d`, using the upstream library as cover for the appended dropper.

    Affected packages

    Package

    Name: tailwindcss-3d-styles

    Purl: pkg:npm/tailwindcss-3d-styles

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.4