Another attack on the NPM supply chain: @ctrl/tinycolor releases a malicious version

PANews reported on September 16th that Scam Sniffer detected another attack targeting the NPM supply chain. @ctrl/tinycolor (downloaded 2.2 million times weekly) released a malicious version that runs an information stealer during npm's postinstall script to scan for and steal sensitive data. This malicious payload abuses the legitimate sensitive information scanning tool TruffleHog. Please check if you have downloaded the affected version, suspend installation/updates, and pin to a known safe version.

Share to:

Author: PA一线

This content is for informational purposes only and does not constitute investment advice.

Follow PANews official accounts, navigate bull and bear markets together
Recommended Reading
2025-12-06 01:43
2025-12-06 00:28
2025-12-05 14:15
2025-12-05 12:30
2025-12-05 06:39
2025-12-05 04:11

Popular Articles

Industry News
Market Trends
Curated Readings

Curated Series

App内阅读