Massive Supply Chain Attack Hijacks ctrl/tinycolor With 2 Million Downloads and Other 40 NPM Packages Exploits September 16, 2025 Share FacebookTwitterPinterestWhatsApp A sophisticated and widespread supply chain attack has struck the NPM ecosystem, compromising the popular @ctrl/tinycolor package, which is downloaded over 2 million times per week. BladeOne Search Latest articles Google uncovers malware using LLMs to operate and evade detection November 5, 2025 Microsoft Hyper-V harnessed for stealthy, persistent malware compromise November 5, 2025 NGate Malware Lets Attackers Withdraw Cash from ATMs Using Stolen Cards November 5, 2025 Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly November 5, 2025 Previous articleSTEM fair at Asbury Woods unites PA Cyber Charter studentsNext article40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials Related articles Google uncovers malware using LLMs to operate and evade detection Exploits November 5, 2025 Microsoft Hyper-V harnessed for stealthy, persistent malware compromise Exploits November 5, 2025 NGate Malware Lets Attackers Withdraw Cash from ATMs Using Stolen Cards Exploits November 5, 2025