GitHub Advisory malware sweep - 9 npm packages (tailwind/animate typosquats, db-* cluster, `vitest-agent`) taken down 2026-07-02
On 2026-07-02 GitHub's Advisory Database dropped 9 CWE-506 Embedded Malicious Code advisories against npm packages published between 2026-05-24 and 2026-07-01. Three distinct micro-clusters were retired within minutes of each other: a Tailwind/animate typosquat trio (animatecss-postcss-plugin, tailwind-animates, tailwind-typography-stylecss), a db-* / cache-* fake-utility quartet, and the standalone vitest-agent Vitest typosquat plus one scoped React Native template. npm replaced every name with a 0.0.1-security holding tarball.
Versions named here: 1.0.0, 1.0.5, 1.0.6