npm

tailwind-elements-ui @1.0.1

Vulnerability report · Last retrieved from osv.dev August 11, 2026 at 2:21 PM UTC

Malicious

OSV ID

MAL-2026-13727

Ecosystem

npm

Summary

No malicious behavior was identified in the package contents. The package name resembles popular Tailwind-related UI libraries, which can indicate name-confusion risk, but no exfiltration, dropper, silent-relay, credential distribution, or install-time remote code execution was observed in the inspected files. Routing to human review so a reviewer can assess name-confusion risk and confirm the package's stated purpose against its contents.

Source: amazon-inspector (75f8605cff87e89b9f1a50c65fc27af278335cf414a8b4fb52ea4090e9fdd71b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.