Massive Supply Chain Attack Hijacks ctrl/tinycolor With 2 Million Downloads and Other 40 NPM Packages Exploits September 16, 2025 Share FacebookXPinterestWhatsApp A sophisticated and widespread supply chain attack has struck the NPM ecosystem, compromising the popular @ctrl/tinycolor package, which is downloaded over 2 million times per week. BladeOne Search Latest articles Keys Under the Mat: Recovering Credentials from the Windows Registry April 14, 2026 Six wealth management awards spotlight Noah’s China-to-global reach April 14, 2026 America has a ‘big AI problem’ and it starts with ‘angry’ Gen Z; shows Stanford survey April 14, 2026 The renewable energy shift is accelerating. And it is reshaping global markets April 14, 2026 Previous articleSTEM fair at Asbury Woods unites PA Cyber Charter studentsNext article40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials Related articles Hackers Distribute ClipBanker Malware via Fake Proxifier Installer On GitHub Exploits April 14, 2026 Fake Proxifier GitHub Installer Spreads ClipBanker Crypto Malware Exploits April 14, 2026 Security Bite Podcast: Atomic Stealer is blurring the line between infostealers and trojans on Mac Exploits April 13, 2026