News Score: Score the News, Sort the News, Rewrite the Headlines

Popular Tinycolor npm Package Compromised in Supply Chain At...

A malicious update to @ctrl/tinycolor (2.2M weekly downloads) was detected on npm as part of a broader supply-chain attack that impacted more than 40 packages spanning multiple maintainers. The compromised versions include a function (NpmModule.updatePackage) that downloads a package tarball, modifies package.json, injects a local script (bundle.js), repacks the archive, and republishes it, enabling automatic trojanization of downstream packages.The issue was first noticed by Daniel dos Santos P...

Read more at socket.dev

© News Score  score the news, sort the news, rewrite the headlines