Home
News Detail

Another attack on the NPM supply chain: @ctrl/tinycolor releases a malicious version

Source: CoinWorld
According to Coinjie.com, Scam Sniffer detected another attack on the NPM supply chain. @ctrl/tinycolor (downloaded 2.2 million times per week) released a malicious version that runs an information stealer during npm's postinstall script to scan and steal sensitive data. This malicious payload abuses the legal sensitive information scanning tool TruffleHog. Please check that you have downloaded the affected version, pause the installation/update, and lock to a known secure version.
Link copied to clipboard