Massive Supply Chain Attack Hijacks ctrl/tinycolor With 2 Million Downloads and Other 40 NPM Packages Exploits September 16, 2025 Share FacebookTwitterPinterestWhatsApp A sophisticated and widespread supply chain attack has struck the NPM ecosystem, compromising the popular @ctrl/tinycolor package, which is downloaded over 2 million times per week. BladeOne Search Latest articles Preview for the Week | Multiple global markets to be closed for the Christmas holiday; U.S. Q3 GDP and other data to be released;... December 21, 2025 Microsoft founder Bill Gates says he was very wrong when he thought that … – The Times of India December 21, 2025 Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence December 21, 2025 Micron Technology (MU) Stock News and Forecasts for Dec. 20, 2025: Earnings Blowout, AI Memory Shortage, and Price Targets Up to $500 December 21, 2025 Previous articleSTEM fair at Asbury Woods unites PA Cyber Charter studentsNext article40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials Related articles Swarm-Based Machine Learning Method Developed for Detecting IoT Malware Exploits December 20, 2025 Swarm AI for IoT Malware Detection Advancements Exploits December 20, 2025 Malware from Roblox Targets Crypto Wallets Exploits December 20, 2025