security holding package
Do not install. Package is flagged as malicious (advisory MAL-2026-316).
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | GHSA-3679-84c2-v5xm | Malicious code in tailwind-merge-v3 (npm) | — |
MAL-2026-316 — Malicious code in tailwind-merge-v3 (npm)Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/tailwind-merge-v3First published · 2026-01-16T16:41:21.122Z
Last updated · 2026-01-16T16:41:21.279Z