In a supply chain attack, the trending npm package, @ctrl/tinycolor, was in the target. Dastardly versions steal secrets through TruffleHog scanning. The npm package ecosystem has been compromised by a massive supply chain attack with a target on the popular package of the ecosystem, which is the tinycolor package of the control group, and over […] The post NPM Supply Attack: Malicious Tinycolor Steals Secrets Using TruffleHog appeared first on Live Bitcoin News.In a supply chain attack, the trending npm package, @ctrl/tinycolor, was in the target. Dastardly versions steal secrets through TruffleHog scanning. The npm package ecosystem has been compromised by a massive supply chain attack with a target on the popular package of the ecosystem, which is the tinycolor package of the control group, and over […] The post NPM Supply Attack: Malicious Tinycolor Steals Secrets Using TruffleHog appeared first on Live Bitcoin News.

NPM Supply Attack: Malicious Tinycolor Steals Secrets Using TruffleHog

2025/09/17 05:30
3 min read

In a supply chain attack, the trending npm package, @ctrl/tinycolor, was in the target. Dastardly versions steal secrets through TruffleHog scanning.

The npm package ecosystem has been compromised by a massive supply chain attack with a target on the popular package of the ecosystem, which is the tinycolor package of the control group, and over forty more packages. 

These malicious versions contain a hidden script that silently robs sensitive developer secrets, and this has caused panic within the development community. 

The attack involves the use of TruffleHog, which is a legitimate secret scanning tool to search and exfiltrate tokens and cloud credentials within infected machines.

Malicious Versions Infect 40+ Packages, Raising Alarms

The altered versions of the @ctrl/tinycolor (4.1.1 and 4.1.2) include a function that downloads a package, alters its contents, loads a malicious script called bundle.js and repackages the package, and republishes it again. 

This creates self-replicating malware that automatically infects subsequent packages maintained by the same authors.

It affected over 40 packages in a variety of maintainers, including other packages scoped to include @ctrl as well as community modules.

The bundle.js file executes on package installation. It then downloads and runs TruffleHog, which searches the machine and repositories of the developer with sensitive tokens, such as GitHub personal access tokens, npm authentication tokens, and cloud service keys, such as AWS and GCP keys. 

On discovering these secrets, it steals them to a hard-coded external webhook address, revealing the personal credentials of the users without their awareness.

It is not a local machine campaign. It also overwrites malicious GitHub Actions workflows in infected repositories. 

Continuous integration settings can activate this workflow to relay stolen secrets over time to facilitate continuous data leaks.

Self-Spreading Malware Creates Cascading Compromise

The malware spreads automatically with the help of the NpmModule.updatePackage function that allows infecting other packages that are maintained by the same developers. 

Such worm-like behaviour creates a chain of supply-chain compromise that spreads automatically after the initial infection, without requiring manual intervention.

Among the environment variables targeted by the attack are those of GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY. 

It authenticates tokens in npm and GitHub API, then employs them to write the durable malicious workflows. 

Such measures keep the malware in place during subsequent CI executions and theft of secrets throughout the development pipelines.

Security professionals encourage developers to issue an emergency audit and delete any affected version of a package. 

They suggest rotating any leaked tokens and secrets and tracking abnormal publishing or network traffic to the exfiltration hosts. Detective Daniel dos Santos Pereira was the first to notice the malicious payload and its effects with the help of the automated malware scanner of Socket.

 

Market Opportunity
SecondLive Logo
SecondLive Price(LIVE)
$0.0000424
$0.0000424$0.0000424
-5.25%
USD
SecondLive (LIVE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

DeFi Technologies' Valour Launches New Bitcoin-Collateralized ETP on London Stock Exchange

DeFi Technologies' Valour Launches New Bitcoin-Collateralized ETP on London Stock Exchange

PANews reported on September 19th that, as the UK gradually relaxes restrictions on digital assets, Valour, a subsidiary of DeFi Technologies, launched a Bitcoin-collateralized ETP on the London Stock Exchange, offering investors the opportunity to earn cryptocurrency returns. This Bitcoin-collateralized ETP offers an annual yield of 1.4%, backed by Bitcoin held in cold wallets and secured by multi-party computation (MCP) technology. Currently, this new Bitcoin-collateralized ETP is only available to institutional and professional investors. The UK will allow retail investors to purchase cryptocurrency ETNs again on October 8, lifting a ban in place since 2021. The announcement did not specify how returns will be generated. However, another Bitcoin ETP listed by Valour on a French exchange generates Bitcoin returns by delegating tokens on Core Chain.
Share
PANews2025/09/19 08:09
Why a Lambo Rental Atlanta Experience Feels Different

Why a Lambo Rental Atlanta Experience Feels Different

Atlanta has a reputation. Some of it’s earned. Some of it’s exaggerated. And some of it lives somewhere between late-night stories, car culture, and the way the
Share
Techbullion2026/02/09 17:43
Treasury opens comment period on GENIUS Act stablecoin rules

Treasury opens comment period on GENIUS Act stablecoin rules

The post Treasury opens comment period on GENIUS Act stablecoin rules appeared on BitcoinEthereumNews.com. The US Department of the Treasury has issued an advance notice of proposed rulemaking (ANPRM) to begin implementing the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS) Act. The measure invites public comments for 30 days following publication in the Federal Register, with submissions viewable on Regulations.gov. The Treasury is seeking input on consumer protection, illicit finance, financial stability, and compliance obligations for stablecoin issuers, as it develops the first formal regulations under the new law. The GENIUS Act, passed earlier this year, marked the first major US legislation focused specifically on payment stablecoins. It directs the Treasury to create a regulatory framework that balances innovation with oversight. This effort follows the Treasury’s August 18 request for comment on detecting illicit activity involving digital assets, which remains open until October 17. While the current notice does not impose new obligations, it signals a pivotal stage in translating the GENIUS Act into enforceable policy. Ethereum stablecoin supply | Blockworks Research Ethereum remains the dominant hub for stablecoins, with a circulating supply of $174 billion on its network, representing 60.7% market share across all chains, according to Blockworks Research data. USDT leads with more than $84 billion deployed on Ethereum, followed by USDC at $47 billion.  Emerging stablecoins such as USDe and USDf have shown sharp growth, expanding their supply by over $141 million and $38 million respectively in recent reporting periods. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/treasury-comment-period-genius
Share
BitcoinEthereumNews2025/09/20 02:00