Massive Supply Chain Attack Hijacks ctrl/tinycolor With 2 Million Downloads and Other 40 NPM Packages Exploits September 16, 2025 Share FacebookTwitterPinterestWhatsApp A sophisticated and widespread supply chain attack has struck the NPM ecosystem, compromising the popular @ctrl/tinycolor package, which is downloaded over 2 million times per week. BladeOne Search Latest articles Iranian Infy APT Resurfaces with New Malware Activity After Years of Silence December 21, 2025 Pastor accused of cyberstalking, harassing estranged wife for years before she died by suicide, police say December 21, 2025 Pastor accused of cyberstalking, harassing estranged wife for years before she died by suicide, police say December 21, 2025 Pastor accused of cyberstalking, harassing estranged wife for years before she died by suicide, police say December 21, 2025 Previous articleSTEM fair at Asbury Woods unites PA Cyber Charter studentsNext article40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials Related articles Swarm-Based Machine Learning Method Developed for Detecting IoT Malware Exploits December 20, 2025 Swarm AI for IoT Malware Detection Advancements Exploits December 20, 2025 Malware from Roblox Targets Crypto Wallets Exploits December 20, 2025