Summary
Togoder Security scanned the npm package @tailwindcss/node@4.3.3 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
Dynamic module loading with computed input
NPS-94DA4673BA88
The code dynamically resolves and imports modules using enhanced-resolve and jiti based on user/input paths. While this is expected behavior for a CSS framework's module loader, it can be abused to load arbitrary modules if an attacker controls the input path.
Module loader hooks registration
NPS-98BFF19C0D12
At import time, it registers module resolution hooks via module.registerHooks or module.register, which modifies the Node.js module resolution behavior globally.
dynamic module loading
NPS-CA913E3E7500
The code wraps dynamic import resolution (resolve/resolveSync) and rewrites the resolved module URL by appending a query parameter derived from the parent module's URL. While not inherently malicious, this behavior can be abused to inject identifiers into module URLs, potentially affecting module caching or loading behavior in unexpected ways.
URL manipulation
NPS-68D5277CDB0E
The function l() reads the 'id' search parameter from the parent module's URL and propagates it to the resolved module's URL. This could be used to influence how modules are cached or resolved, potentially enabling cache poisoning or module confusion if the 'id' parameter is attacker-controlled.
Global hook functions
NPS-F92683864E03
The code checks for global functions __tw_load and __tw_resolve and uses them if present. These could be set by other code in the same process to hijack module resolution/loading.
File system access
NPS-E52314487222
The code reads files, stats files, and accesses directories during module resolution. This is expected for a CSS build tool but could be used to probe the filesystem.
Environment variable access
NPS-BA10881A4D95
It reads process.env.DEBUG and process.env.NODE_PATH for configuration. DEBUG is used for instrumentation reporting; NODE_PATH for module resolution. No credential harvesting detected.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm-cache.loader.mjs | medium | The module dynamically rewrites resolved import URLs using a query parameter from the parent URL; no data exfiltration, credential harvesting, obfuscation, or command execution was detected, but the URL manipulation warrants caution. |
| dist/index.js | medium | This is the Tailwind CSS v4 bundler code; it performs dynamic module loading and filesystem resolution which is expected but has security implications if inputs are untrusted. |
| dist/index.mjs | safe | The code is a minified build artifact of the Tailwind CSS Node.js package, containing no malicious patterns such as data exfiltration, credential harvesting, or unauthorized code execution. |
| dist/require-cache.js | safe | The file only provides a utility to clear Node.js require cache entries and contains no malicious patterns. |
Frequently asked questions
Is @tailwindcss/node safe to use?
No confirmed malware was found in @tailwindcss/node@4.3.3, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does @tailwindcss/node contain malware?
No malware was identified in @tailwindcss/node@4.3.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @tailwindcss/node checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @tailwindcss/node together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tailwindcss/node@4.3.3, cost nothing.