The NPM package "@ctrl/tinycolor" was attacked by supply chain, containing malicious information stolen
Source: ForesightNews
Time: 2025-09-16 11:02:10
According to Scam Sniffer monitoring, the NPM package "@ctrl/tinycolor" with a weekly download volume of 2.2 million was implanted into a malicious version. It runs an information stealer during the npm postinstall process, and uses the legal tool TruffleHog to scan and leak sensitive data. At present, about 40 related dependencies have been affected. Users should immediately check whether the affected version is installed, pause updates, and lock the secure version.