VDB

GCVE-110-OSM-2026-13415

GCVE-110-OSM-2026-13415
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published October 8, 2026
animatecss-tailwind-adapter 2.0.6 was published to npm on 2026-07-28 by the account grant587holloway. The package is part of a fake job interview campaign that targets developers, using the same method as the "Contagious Interview" campaign. A fake company sends a take-home coding assessment repository. The repository commits a web/.npmrc containing a plaintext npm auth token, and its tailwind.config.js loads this package as a Tailwind CSS plugin. The package presents itself as an Animate.css integration ("A configurable, namespaced Animate.css integration for Tailwind CSS", main plugin.js) but declares a runtime dependency on a private scoped npm package (@aaron205whitmore/postcss-animate-utils) that is not publicly readable, so npm audit and public scanners cannot see it; it only resolves with the token committed in the lure repository. The package has no install scripts, so --ignore-scripts does not help: the code runs when Tailwind loads the config, i.e. on `npm run dev` / `next dev`. Public analysis of the earlier package in this chain (animatecss-tailwind-adapter, by Yunus Aydın) reports that the private package contacts an operator-controlled server and runs the code it receives with full Node.js privileges. This is the earlier version of the chain, analysed by Yunus Aydın, whose analysis found the private dependency contacts an operator server and executes the code it returns. Its repository field uses the same GitHub account (sericpieap) as animatecss-tailwind-bridge; neither repository is publicly accessible. Related packages from the same template (same description, main file, dependency list and 2.0.x versioning, each published by a different single-use npm account): animatecss-tailwind-adapter 2.0.6 (2026-07-28, depends on private @aaron205whitmore/postcss-animate-utils), animatecss-tailwind-bridge 2.0.6 (2026-09-13, depends on private @jasperquinn/postcss-motion-helpers) and tailwind-animatecss-uniform 2.0.7 (2026-09-28, depends on private @jasperquinn/postcss-motion-helpers). ENTRY plugin.js (main: plugin.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownanimatecss-tailwind-adapterall (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›