The NPM package "@ctrl/tinycolor" with a weekly download volume of 2.2 million times was attacked by the supply chain, containing a malicious information stealer
Source: ChainCatcher
Time: 2025-09-16 09:53:05
According to ChainCatcher, according to Scam Sniffer warning, the NPM package "@ctrl/tinycolor" with a weekly download volume of 2.2 million was implanted into a malicious version, running an information stealer during the npm postinstall process, using the legal tool TruffleHog to scan and leak sensitive data. At present, about 40 related dependencies have been affected. Users should immediately check whether the affected version is installed, pause updates, and lock the secure version.