In a supply chain attack, the trending npm package, @ctrl/tinycolor, was in the target. Dastardly versions steal secrets through TruffleHog scanning. The npm package ecosystem has been compromised by a massive supply chain attack with a target on the popular package of the ecosystem, which is the tinycolor package of the control group, and over […] The post NPM Supply Attack: Malicious Tinycolor Steals Secrets Using TruffleHog appeared first on Live Bitcoin News.In a supply chain attack, the trending npm package, @ctrl/tinycolor, was in the target. Dastardly versions steal secrets through TruffleHog scanning. The npm package ecosystem has been compromised by a massive supply chain attack with a target on the popular package of the ecosystem, which is the tinycolor package of the control group, and over […] The post NPM Supply Attack: Malicious Tinycolor Steals Secrets Using TruffleHog appeared first on Live Bitcoin News.

NPM Supply Attack: Malicious Tinycolor Steals Secrets Using TruffleHog

In a supply chain attack, the trending npm package, @ctrl/tinycolor, was in the target. Dastardly versions steal secrets through TruffleHog scanning.

The npm package ecosystem has been compromised by a massive supply chain attack with a target on the popular package of the ecosystem, which is the tinycolor package of the control group, and over forty more packages. 

These malicious versions contain a hidden script that silently robs sensitive developer secrets, and this has caused panic within the development community. 

The attack involves the use of TruffleHog, which is a legitimate secret scanning tool to search and exfiltrate tokens and cloud credentials within infected machines.

Malicious Versions Infect 40+ Packages, Raising Alarms

The altered versions of the @ctrl/tinycolor (4.1.1 and 4.1.2) include a function that downloads a package, alters its contents, loads a malicious script called bundle.js and repackages the package, and republishes it again. 

This creates self-replicating malware that automatically infects subsequent packages maintained by the same authors.

It affected over 40 packages in a variety of maintainers, including other packages scoped to include @ctrl as well as community modules.

The bundle.js file executes on package installation. It then downloads and runs TruffleHog, which searches the machine and repositories of the developer with sensitive tokens, such as GitHub personal access tokens, npm authentication tokens, and cloud service keys, such as AWS and GCP keys. 

On discovering these secrets, it steals them to a hard-coded external webhook address, revealing the personal credentials of the users without their awareness.

It is not a local machine campaign. It also overwrites malicious GitHub Actions workflows in infected repositories. 

Continuous integration settings can activate this workflow to relay stolen secrets over time to facilitate continuous data leaks.

Self-Spreading Malware Creates Cascading Compromise

The malware spreads automatically with the help of the NpmModule.updatePackage function that allows infecting other packages that are maintained by the same developers. 

Such worm-like behaviour creates a chain of supply-chain compromise that spreads automatically after the initial infection, without requiring manual intervention.

Among the environment variables targeted by the attack are those of GITHUB_TOKEN, NPM_TOKEN, AWS_ACCESS_KEY_ID, and AWS_SECRET_ACCESS_KEY. 

It authenticates tokens in npm and GitHub API, then employs them to write the durable malicious workflows. 

Such measures keep the malware in place during subsequent CI executions and theft of secrets throughout the development pipelines.

Security professionals encourage developers to issue an emergency audit and delete any affected version of a package. 

They suggest rotating any leaked tokens and secrets and tracking abnormal publishing or network traffic to the exfiltration hosts. Detective Daniel dos Santos Pereira was the first to notice the malicious payload and its effects with the help of the automated malware scanner of Socket.

 

Market Opportunity
SecondLive Logo
SecondLive Price(LIVE)
$0.00003192
$0.00003192$0.00003192
-1.66%
USD
SecondLive (LIVE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

In 2025, global cryptocurrency investors will rush to purchase Pioneer Hash smart cloud mining contracts, allowing you to earn a daily incomethatneverstops!

In 2025, global cryptocurrency investors will rush to purchase Pioneer Hash smart cloud mining contracts, allowing you to earn a daily incomethatneverstops!

The post In 2025, global cryptocurrency investors will rush to purchase Pioneer Hash smart cloud mining contracts, allowing you to earn a daily incomethatneverstops! appeared on BitcoinEthereumNews.com. In recent years, as digital assets have further entered the mainstream, Pioneer Hash has grown into a top global cloud mining service provider, serving over 6 million users in over 180 countries. The platform allows users to mine cryptocurrencies such as Bitcoin (BTC), Ethereum (ETH), Solana (SOL), Ripple (XRP), and Dogecoin (DOGE) without purchasing expensive hardware or paying for electricity. Pioneer Hash’s contracts, which transform idle assets into high-yield mining schemes, have attracted numerous cryptocurrency holders, with some advanced users reporting daily returns of up to $8,999 or more. This model is particularly suitable for both novice and professional investors, and cloud mining is rapidly becoming one of the most convenient ways for individuals to earn passive crypto income. Bitcoin mining is often associated with expensive hardware, high electricity costs, and technical know-how. But in 2025, cloud mining allows anyone to start mining, no experience required. Instead of setting up a mining rig at home, a simple contract gives remote access to an industrial-scale mining farm. These services allow beginners to earn Bitcoin securely, transparently, and efficiently, using only their phone or computer. How to join Pioneer Hash and start earning a stable daily income? 1. Visit the official website. Register an account at pioneerhash.com to quickly begin your cloud mining journey. 2. Complete registration and receive a $15 welcome bonus. Fill in your basic information and, upon successful registration, receive a $15 trial bonus from the platform. Try cloud mining at no cost. 3. Choose a contract. Choose the appropriate cloud computing power contract. No technical knowledge is required. The platform automatically schedules mining pools and computing power, and mining and generating revenue will begin within 24 hours. 4. Referral Rewards: Invite friends and earn commissions easily. Level 1 referral: Receive a 3% bonus. Level 2 referral: Receive a…
Share
BitcoinEthereumNews2025/09/22 20:51
MakinaFi suffered an attack that resulted in the loss of approximately 1299 ETH, with some funds being preemptively processed by MEV.

MakinaFi suffered an attack that resulted in the loss of approximately 1299 ETH, with some funds being preemptively processed by MEV.

PANews reported on January 20th that, according to PeckShieldAlert, the MakinaFi platform was attacked, with hackers stealing approximately 1,299 ETH, worth about
Share
PANews2026/01/20 12:32
Magic Eden co-founder sees 'speculation supercycle' ahead

Magic Eden co-founder sees 'speculation supercycle' ahead

Trading volumes in prediction markets are higher than ever, with Monday seeing a record $814.2 million worth of trades placed on Kalshi, Polymarket, and other platforms
Share
Coinstats2026/01/20 12:12