{"id":"MAL-2026-15912","summary":"Malicious code in tailwind-aspect (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e6ba6037f5f2f65c0ceef0ba5bd8da931b7860a85e7a38fb2703ad4cd7672ddf)\nThe package's main entrypoint unconditionally downloads a JavaScript file from the hardcoded plain-HTTP bare-IP URL http://23.27.245.100/index.js, writes it to./inout.js, and require()s it every time a consumer imports the package. The fetched content is unpinned, unverified, and served over cleartext HTTP, giving the operator of that IP (and any on-path attacker) arbitrary code execution on the installer's machine at import time. The package name and repository metadata impersonate the official @tailwindcss/aspect-ratio plugin (repository points at tailwindlabs/tailwindcss-aspect-ratio), providing cover for the loader; the remote fetch has no relationship to any Tailwind plugin functionality.\n","modified":"2026-09-04T05:45:05.630189172Z","published":"2026-09-04T05:19:41Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-019478","import_time":"2026-09-04T05:39:32.835224008Z","modified_time":"2026-09-04T05:19:41Z","sha256":"e6ba6037f5f2f65c0ceef0ba5bd8da931b7860a85e7a38fb2703ad4cd7672ddf","source":"amazon-inspector","versions":["0.4.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tailwind-aspect/v/0.4.2"}],"affected":[{"package":{"name":"tailwind-aspect","ecosystem":"npm","purl":"pkg:npm/tailwind-aspect"},"versions":["0.4.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"2675b2db17a311c8c48797fb24aaeed4d548c598f165f7a55ce5f74f76669f62","tlsh":"f43165b1068185044861769793619c42e6dbb1b4ce7e8082ead54c7947c1dd1bb12ebb","path":"src/index.js"},{"path":"package.json","sha256":"a6ec6fac54dc0d8b2d6058238711ead8eb3923c2446df4efeb53cf0b85319c15","tlsh":"1cf07822ce240e7305e4716197ba0597a2a318274418bc0e31c2860c8b8c5aff0f966d"}],"package_integrity":[{"filename":"tailwind-aspect-0.4.2.tgz","hashes":{"sha1":"3bbee69f54d82f387bf5fb3bca01d7e42cf6346a","sha512_sri":"sha512-SVOBQKYnHRoBT/H4AF7qIbf3SE632ZVJnknnwQYnqd9+2NsCYDB7/7iP1+K51P9AT8pxbkn8KACV/CLbdNPL0g=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tailwind-aspect/MAL-2026-15912.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}