# @tailwindcss/oxide@4.3.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:20.000Z
- Files reviewed: 1
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/@tailwindcss/oxide
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @tailwindcss/oxide@4.3.3 on Oct 6, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading from environment variable

Finding ID: `NPS-EDFF0BEB5E2B`

File: `index.js:63`

The requireNative() function loads a native .node binding from an arbitrary path specified in the NAPI_RS_NATIVE_LIBRARY_PATH environment variable. If an attacker can control that environment variable, they can force the package to load an arbitrary native library, leading to code execution.

### [low] Filesystem access outside package scope

Finding ID: `NPS-8B009A7200B0`

File: `index.js:33`

Reads /usr/bin/ldd from the host filesystem at import time for musl detection. This is a read-only probe of a standard system binary and is not itself exfiltration, but it is host filesystem access performed during module initialization.

### [low] Shell command execution at import time

Finding ID: `NPS-229BEC2E09F3`

File: `index.js:53`

isMuslFromChildProcess executes 'ldd --version' via child_process.execSync at module load time on Linux to detect musl libc. This is legitimate musl-detection logic but still represents a process spawn happening as a side-effect of importing the module.

## Files reviewed

- `index.js` (medium): This is an auto-generated NAPI-RS loader for the @tailwindcss/oxide native binding; it performs platform detection and dynamic native/WASI binding loading, with no signs of exfiltration, credential harvesting, obfuscation, or backdoor behavior, but it does load native code paths from an environment variable and executes shell/read commands at import time.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
