MAL-2026-17666

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/animatecss-tailwind-bridge/MAL-2026-17666.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17666
Published
2026-10-07T18:36:40Z
Modified
2026-10-08T05:15:04Z
Summary
Malicious code in animatecss-tailwind-bridge (npm)
Details

animatecss-tailwind-bridge 2.0.6 was published to npm on 2026-09-13 by the account bennetwild. The package is part of a fake job interview campaign that targets developers, using the same method as the "Contagious Interview" campaign. A fake company sends a take-home coding assessment repository. The repository commits a web/.npmrc containing a plaintext npm auth token, and its tailwind.config.js loads this package as a Tailwind CSS plugin. The package presents itself as an Animate.css integration ("A configurable, namespaced Animate.css integration for Tailwind CSS", main plugin.js) but declares a runtime dependency on a private scoped npm package (@jasperquinn/postcss-motion-helpers) that is not publicly readable, so npm audit and public scanners cannot see it; it only resolves with the token committed in the lure repository. The package has no install scripts, so --ignore-scripts does not help: the code runs when Tailwind loads the config, i.e. on npm run dev / next dev. Public analysis of the earlier package in this chain (animatecss-tailwind-adapter, by Yunus Aydın) reports that the private package contacts an operator-controlled server and runs the code it receives with full Node.js privileges. A public write-up by a targeted developer describes this package as the dependency in a lure repository for a Solana copy-trading dashboard from a fake company "BlockRoute Labs" (blockroutelabs.com), recruited through Djinni.co. It depends on the same private package as tailwind-animatecss-uniform, which was found in a separate lure. The package's repository field points to a GitHub repository that is not publicly accessible. Related packages from the same template (same description, main file, dependency list and 2.0.x versioning, each published by a different single-use npm account): animatecss-tailwind-adapter 2.0.6 (2026-07-28, depends on private @aaron205whitmore/postcss-animate-utils), animatecss-tailwind-bridge 2.0.6 (2026-09-13, depends on private @jasperquinn/postcss-motion-helpers) and tailwind-animatecss-uniform 2.0.7 (2026-09-28, depends on private @jasperquinn/postcss-motion-helpers).

References
Credits

Affected packages

npm / animatecss-tailwind-bridge

Package

Name
animatecss-tailwind-bridge
View open source insights on deps.dev
Purl
pkg:npm/animatecss-tailwind-bridge

Affected ranges

Affected versions

2.*
2.0.6

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/animatecss-tailwind-bridge/MAL-2026-17666.json"