critical

Malware in npm package tailwindcss-animotion

malicious-version-published · active

A malicious version of the npm package tailwindcss-animotion was published containing malware. Any system with this package installed should be considered fully compromised, and all secrets and keys on that system should be rotated immediately from a separate, clean machine.

Affected packages

Sources