LWA-2026-6269 MAL-2026-10550 ↗ confirmed malware

better-tailwindcss@4.6.3

Malicious code in better-tailwindcss (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool TransferT1059.007 · JavaScript

Analysis

better-tailwindcss is a combosquat (tailwindcss with "better-" prefix) that contains no Tailwind CSS functionality. The package declares a self-referencing dependency from an external HTTP server at hxxp://pack[.]nppacks[.]com/npm/better-tailwindcss in both dependencies and devDependencies. When npm install resolves this dependency, it fetches a tarball from the attacker-controlled host, enabling arbitrary remote code delivery transparently during installation. Dependencies include axios, node-fetch, and ws (networking libraries). No repository URL is declared.

analyzed by
Leitwacht
first seen
Jul 2, 2026, 06:18 PM
analyzed
Jul 2, 2026, 06:21 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.