Another attack on the NPM supply chain: @ctrl/tinycolor releases a malicious version
Source: CoinWorld
Time: 2025-09-16 09:36:03
According to Coinjie.com, Scam Sniffer detected another attack on the NPM supply chain. @ctrl/tinycolor (downloaded 2.2 million times per week) released a malicious version that runs an information stealer during npm's postinstall script to scan and steal sensitive data. This malicious payload abuses the legal sensitive information scanning tool TruffleHog. Please check that you have downloaded the affected version, pause the installation/update, and lock to a known secure version.