Togoder security

npm package security report

@tailwindcss/node@4.3.3 security report

Risky patterns found that deserve a look.

Needs review Version 4.3.3 Files reviewed 4 Size 109.1 KB Scanned

Summary

Togoder Security scanned the npm package @tailwindcss/node@4.3.3 on Oct 6, 2026. An AI review of 4 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
5
low

Findings 7

medium

Dynamic module loading with computed input

NPS-94DA4673BA88

The code dynamically resolves and imports modules using enhanced-resolve and jiti based on user/input paths. While this is expected behavior for a CSS framework's module loader, it can be abused to load arbitrary modules if an attacker controls the input path.

dist/index.js
medium

Module loader hooks registration

NPS-98BFF19C0D12

At import time, it registers module resolution hooks via module.registerHooks or module.register, which modifies the Node.js module resolution behavior globally.

dist/index.js
low

dynamic module loading

NPS-CA913E3E7500

The code wraps dynamic import resolution (resolve/resolveSync) and rewrites the resolved module URL by appending a query parameter derived from the parent module's URL. While not inherently malicious, this behavior can be abused to inject identifiers into module URLs, potentially affecting module caching or loading behavior in unexpected ways.

dist/esm-cache.loader.mjs
low

URL manipulation

NPS-68D5277CDB0E

The function l() reads the 'id' search parameter from the parent module's URL and propagates it to the resolved module's URL. This could be used to influence how modules are cached or resolved, potentially enabling cache poisoning or module confusion if the 'id' parameter is attacker-controlled.

dist/esm-cache.loader.mjs
low

Global hook functions

NPS-F92683864E03

The code checks for global functions __tw_load and __tw_resolve and uses them if present. These could be set by other code in the same process to hijack module resolution/loading.

dist/index.js
low

File system access

NPS-E52314487222

The code reads files, stats files, and accesses directories during module resolution. This is expected for a CSS build tool but could be used to probe the filesystem.

dist/index.js
low

Environment variable access

NPS-BA10881A4D95

It reads process.env.DEBUG and process.env.NODE_PATH for configuration. DEBUG is used for instrumentation reporting; NODE_PATH for module resolution. No credential harvesting detected.

dist/index.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm-cache.loader.mjs medium The module dynamically rewrites resolved import URLs using a query parameter from the parent URL; no data exfiltration, credential harvesting, obfuscation, or command execution was detected, but the URL manipulation warrants caution.
dist/index.js medium This is the Tailwind CSS v4 bundler code; it performs dynamic module loading and filesystem resolution which is expected but has security implications if inputs are untrusted.
dist/index.mjs safe The code is a minified build artifact of the Tailwind CSS Node.js package, containing no malicious patterns such as data exfiltration, credential harvesting, or unauthorized code execution.
dist/require-cache.js safe The file only provides a utility to clear Node.js require cache entries and contains no malicious patterns.

Frequently asked questions

Is @tailwindcss/node safe to use?

No confirmed malware was found in @tailwindcss/node@4.3.3, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does @tailwindcss/node contain malware?

No malware was identified in @tailwindcss/node@4.3.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @tailwindcss/node checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @tailwindcss/node together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @tailwindcss/node@4.3.3, cost nothing.

Related security reports