Massive Supply Chain Attack Hijacks ctrl/tinycolor With 2 Million Downloads and Other 40 NPM Packages Exploits September 16, 2025 Share FacebookXPinterestWhatsApp A sophisticated and widespread supply chain attack has struck the NPM ecosystem, compromising the popular @ctrl/tinycolor package, which is downloaded over 2 million times per week. BladeOne Search Latest articles How a self-taught Vietnamese high schooler built the malware that infected 94,000 computers worldwide March 28, 2026 Backdoored Telnyx PyPI package pushes malware hidden in WAV audio March 27, 2026 Quote of the day by Clint Eastwood: ‘A war is a horrible thing, but it’s also a…’ – lessons on war, unit March 27, 2026 Quote of the day by Clint Eastwood: ‘A war is a horrible thing, but it’s also a…’ – lessons on war, unit March 27, 2026 Previous articleSTEM fair at Asbury Woods unites PA Cyber Charter studentsNext article40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials Related articles How a self-taught Vietnamese high schooler built the malware that infected 94,000 computers worldwide Exploits March 28, 2026 Backdoored Telnyx PyPI package pushes malware hidden in WAV audio Exploits March 27, 2026 This new scam could trick you into downloading malware Exploits March 27, 2026