tailwind-core@4.3.0
Malicious code in tailwind-core (npm)
Analysis
tailwind-core@4.3.0 is a combosquat of the legitimate tailwindcss CSS framework, published by a known supply-chain attacker account. The package ships a functional CSS compiler as cover but contains a base64 decoding function (Buffer.from base64 to string) paired with a new Function(code) call that evaluates decoded content — a dormant eval-decoder channel for executing hidden payloads. The package is published under the name tailwind-core to trick developers mistyping tailwindcss, on a GitHub repository at github[.]com/QaLemos/tailwind-core.git — an unaffiliated user, not the official tailwindlabs organization.
- analyzed by
- Leitwacht
- first seen
- Jun 14, 2026, 02:03 PM
- analyzed
- Jun 14, 2026, 02:04 PM
Related advisories
- stylelint-standard@1.2.0
- strutil-kit@1.0.0
- str-master@1.0.11
- strmagic-kit@1.0.0
- stringsculpt-kit@1.0.0
- stacknova@1.0.0
- sqrt-bn-enhanced@2.0.9
- sort-btree@2.1.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.