better-tailwindcss@4.6.3
Malicious code in better-tailwindcss (npm)
Analysis
better-tailwindcss is a combosquat (tailwindcss with "better-" prefix) that contains no Tailwind CSS functionality. The package declares a self-referencing dependency from an external HTTP server at hxxp://pack[.]nppacks[.]com/npm/better-tailwindcss in both dependencies and devDependencies. When npm install resolves this dependency, it fetches a tarball from the attacker-controlled host, enabling arbitrary remote code delivery transparently during installation. Dependencies include axios, node-fetch, and ws (networking libraries). No repository URL is declared.
- analyzed by
- Leitwacht
- first seen
- Jul 2, 2026, 06:18 PM
- analyzed
- Jul 2, 2026, 06:21 PM
Related advisories
- transform-es2015-sticky-regex@6.24.3
- chai-await-dom@1.3.7
- chai-as-align@7.1.0
- db-query-log@1.0.2
- marked-prettier@1.0.5
- execfences@5.0.2
- react-jsonwebtoken@9.0.5
- npm-rce-poc@1.0.13
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.