Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Popular Tinycolor npm Package Compromised in Supply Chain At...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
721
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

A supply chain attack compromised the popular npm package `@ctrl/tinycolor`, along with over 40 other packages, affecting numerous maintainers and resulting in the injection of a malicious script, `bundle.js`, into these packages. This script enables the automatic trojanization of downstream packages by downloading a package tarball, modifying its `package.json`, and republishing it. The attack was initially identified by Daniel dos Santos Pereira, and further analysis by Socket's automated malware detection revealed the threat's presence in additional packages. The malicious script executes TruffleHog, a legitimate secret scanner, to search for tokens and cloud credentials, creating GitHub Actions workflows and exfiltrating data to a specified webhook. The attack highlights vulnerabilities in package management systems, prompting immediate guidance to uninstall affected versions, audit environments, and rotate exposed credentials. A comprehensive technical analysis and further remediation guidance are in development as part of the ongoing investigation.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.