critical

Malware in npm package clsx-tailwind

malicious-version-published · active

The npm package clsx-tailwind has been identified as malicious. Any system where it was installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a different machine.

Affected packages

Sources