VDB

GCVE-110-OSM-2026-13417

GCVE-110-OSM-2026-13417
Advisory PublishedCVSS 5.4/10
Vulnetix · Advisory published October 8, 2026
tailwind-animatecss-uniform 2.0.7 was published to npm on 2026-09-28 by the account ares0320. The package is part of a fake job interview campaign that targets developers, using the same method as the "Contagious Interview" campaign. A fake company sends a take-home coding assessment repository. The repository commits a web/.npmrc containing a plaintext npm auth token, and its tailwind.config.js loads this package as a Tailwind CSS plugin. The package presents itself as an Animate.css integration ("A configurable, namespaced Animate.css integration for Tailwind CSS", main plugin.js) but declares a runtime dependency on a private scoped npm package (@jasperquinn/postcss-motion-helpers) that is not publicly readable, so npm audit and public scanners cannot see it; it only resolves with the token committed in the lure repository. The package has no install scripts, so --ignore-scripts does not help: the code runs when Tailwind loads the config, i.e. on `npm run dev` / `next dev`. Public analysis of the earlier package in this chain (animatecss-tailwind-adapter, by Yunus Aydın) reports that the private package contacts an operator-controlled server and runs the code it receives with full Node.js privileges. Observed directly: the lure was a "backend engineer assessment" for a fake company "Nodveta" (nodveta.com), posted as a job on Torre.ai (https://torre.ai/s/dphYpcyPn1) and shared as the private GitHub repository Nodveta-Infra/backend-engineer-assessment (a Hardhat / Express / Next.js pharmaceutical cold-chain dApp). The repository's commits are dated 2026-09-20/21, but the GitHub organization was created on 2026-09-29 and this package was published on 2026-09-28, so the history was backdated. The final commits add web/.npmrc (npm auth token) and a web/AGENTS.md + CLAUDE.md written for AI coding agents: they claim the project uses an unfamiliar Next.js version, send the agent to read docs inside node_modules (which requires installing dependencies), and tell it to commit the file. The package's repository field points to a GitHub repository that is not publicly accessible. Related packages from the same template (same description, main file, dependency list and 2.0.x versioning, each published by a different single-use npm account): animatecss-tailwind-adapter 2.0.6 (2026-07-28, depends on private @aaron205whitmore/postcss-animate-utils), animatecss-tailwind-bridge 2.0.6 (2026-09-13, depends on private @jasperquinn/postcss-motion-helpers) and tailwind-animatecss-uniform 2.0.7 (2026-09-28, depends on private @jasperquinn/postcss-motion-helpers). ENTRY plugin.js (main: plugin.js)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
unknowntailwind-animatecss-uniformall (affected)—

References

advisory
vendor

Browse GCVE Records

3,328 records in the GCVE database · Updated October 10, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›