๐จ Malicious update to @ctrl/tinycolor on npm is part of an active supply chain attack hitting 40+ packages across multiple maintainers. Audit & remove affected versions.
Our analysis of the malware: socket.dev/blog/tinycol... #NodeJS #JavaScript
Posts by Bryce Boe
7 months ago
30
20
0
14
Honestly serious: JUST DON'T UPDATE PACKAGES RIGHT NOW.
It is unclear to me yet, but this is looking pretty wide spread. Better be safe than sorry, just go touch some grass.
7 months ago
73
39
4
6
Do not update to @ctrl/tinycolor@4.1.2. It has malware that is currently live on npm.
7 months ago
19
4
1
1
Thanks!
2 years ago
0
0
0
0
I'm excited to finally be on #bluesky. Now I need to curate my feeds.
2 years ago
5
0
1
0