Settings

Theme

Ctrl/tinycolor and 40 NPM Packages Compromised

stepsecurity.io

3 points by kurmiashish 4 months ago · 1 comment

Reader

kurmiashishOP 4 months ago

The popular @ctrl/tinycolor package, which receives over 2 million weekly downloads, has been compromised along with more than 40 other packages across multiple maintainers. This attack demonstrates a concerning evolution in supply chain threats - the malware includes a self-propagating mechanism that automatically infects downstream packages, creating a cascading compromise across the ecosystem.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection