VDB
GCVE-110-OSM-2026-13415
GCVE-110-OSM-2026-13415
Advisory PublishedCVSS 9.6/10
animatecss-tailwind-adapter 2.0.6 was published to npm on 2026-07-28 by the account grant587holloway. The package is part of a fake job interview campaign that targets developers, using the same method as the "Contagious Interview" campaign. A fake company sends a take-home coding assessment repository. The repository commits a web/.npmrc containing a plaintext npm auth token, and its tailwind.config.js loads this package as a Tailwind CSS plugin. The package presents itself as an Animate.css integration ("A configurable, namespaced Animate.css integration for Tailwind CSS", main plugin.js) but declares a runtime dependency on a private scoped npm package (@aaron205whitmore/postcss-animate-utils) that is not publicly readable, so npm audit and public scanners cannot see it; it only resolves with the token committed in the lure repository. The package has no install scripts, so --ignore-scripts does not help: the code runs when Tailwind loads the config, i.e. on `npm run dev` / `next dev`. Public analysis of the earlier package in this chain (animatecss-tailwind-adapter, by Yunus Aydın) reports that the private package contacts an operator-controlled server and runs the code it receives with full Node.js privileges. This is the earlier version of the chain, analysed by Yunus Aydın, whose analysis found the private dependency contacts an operator server and executes the code it returns. Its repository field uses the same GitHub account (sericpieap) as animatecss-tailwind-bridge; neither repository is publicly accessible. Related packages from the same template (same description, main file, dependency list and 2.0.x versioning, each published by a different single-use npm account): animatecss-tailwind-adapter 2.0.6 (2026-07-28, depends on private @aaron205whitmore/postcss-animate-utils), animatecss-tailwind-bridge 2.0.6 (2026-09-13, depends on private @jasperquinn/postcss-motion-helpers) and tailwind-animatecss-uniform 2.0.7 (2026-09-28, depends on private @jasperquinn/postcss-motion-helpers).
ENTRY
plugin.js (main: plugin.js)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | animatecss-tailwind-adapter | all (affected) | — |
Aliases
Browse GCVE Records
3,328 records in the GCVE database · Updated October 10, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.