Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

npm Malware Outbreak: Tinycolor and CrowdStrike Packages Compromised

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
972
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent supply chain attack affecting npm packages has been identified, with over 582 compromised package versions from 194 distinct packages, including popular ones like @ctrl/tinycolor. The attack, which began on September 15, involves malicious code that spreads like a virus by using the npm credentials of compromised developers to infect other packages. This code exfiltrates secrets from infected systems and GitHub repositories and replicates itself across npm packages. While some malicious packages remain available, organizations are urged to take immediate preventative actions, such as stopping npm usage in CI/CD pipelines and reviewing package-lock.json files for references to infected versions. Mitigation strategies include using lockfiles pinned to known-good versions, cleaning caches, and implementing cooldown options to minimize the risk of downloading compromised packages. The attack's full impact remains unknown, and efforts to identify and remove infected versions continue.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.