Skip to content

[urgent] Malicious code in the tailwind.config.js #33

Description

@Potat0-0

Describe the bug
tailwind.config.js has been infected!

To Reproduce
Steps to reproduce the behavior:

  1. Go to 'tailwind.config.js'
  2. Scroll right to the end
  3. See malicious, obfuscated code.

Expected behavior
You should see executable js script.

Screenshots

Image

Additional context
This kind of attack surface -> incident report

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions