Ctrl/tinycolor and 40 NPM Packages Compromised

3 kurmiashish 1 9/16/2025, 1:44:20 AM stepsecurity.io ↗

Comments (1)

kurmiashish · 34m ago
The popular @ctrl/tinycolor package, which receives over 2 million weekly downloads, has been compromised along with more than 40 other packages across multiple maintainers. This attack demonstrates a concerning evolution in supply chain threats - the malware includes a self-propagating mechanism that automatically infects downstream packages, creating a cascading compromise across the ecosystem.