{"id":"MAL-2026-17666","summary":"Malicious code in animatecss-tailwind-bridge (npm)","details":"animatecss-tailwind-bridge 2.0.6 was published to npm on 2026-09-13 by the account bennetwild. The package is part of a fake job interview campaign that targets developers, using the same method as the \"Contagious Interview\" campaign. A fake company sends a take-home coding assessment repository. The repository commits a web/.npmrc containing a plaintext npm auth token, and its tailwind.config.js loads this package as a Tailwind CSS plugin. The package presents itself as an Animate.css integration (\"A configurable, namespaced Animate.css integration for Tailwind CSS\", main plugin.js) but declares a runtime dependency on a private scoped npm package (@jasperquinn/postcss-motion-helpers) that is not publicly readable, so npm audit and public scanners cannot see it; it only resolves with the token committed in the lure repository. The package has no install scripts, so --ignore-scripts does not help: the code runs when Tailwind loads the config, i.e. on `npm run dev` / `next dev`. Public analysis of the earlier package in this chain (animatecss-tailwind-adapter, by Yunus Aydın) reports that the private package contacts an operator-controlled server and runs the code it receives with full Node.js privileges. A public write-up by a targeted developer describes this package as the dependency in a lure repository for a Solana copy-trading dashboard from a fake company \"BlockRoute Labs\" (blockroutelabs.com), recruited through Djinni.co. It depends on the same private package as tailwind-animatecss-uniform, which was found in a separate lure. The package's repository field points to a GitHub repository that is not publicly accessible. Related packages from the same template (same description, main file, dependency list and 2.0.x versioning, each published by a different single-use npm account): animatecss-tailwind-adapter 2.0.6 (2026-07-28, depends on private @aaron205whitmore/postcss-animate-utils), animatecss-tailwind-bridge 2.0.6 (2026-09-13, depends on private @jasperquinn/postcss-motion-helpers) and tailwind-animatecss-uniform 2.0.7 (2026-09-28, depends on private @jasperquinn/postcss-motion-helpers).","modified":"2026-10-08T05:15:04.279904792Z","published":"2026-10-07T18:36:40Z","references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/animatecss-tailwind-bridge"}],"affected":[{"package":{"name":"animatecss-tailwind-bridge","ecosystem":"npm","purl":"pkg:npm/animatecss-tailwind-bridge"},"versions":["2.0.6"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/animatecss-tailwind-bridge/MAL-2026-17666.json"}}],"schema_version":"1.9.0","credits":[{"name":"juanda2222","contact":["https://github.com/juanda2222"],"type":"FINDER"}]}