Vulnerability library
Security checkSeptember 15, 2025

[email protected] contains malware after npm account takeover

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmcolor

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

On 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker’s own addresses from within browser environments.

Recommendation

Update the color package to the latest compatible version. Followings are version details:

  • Affected version(s): = 5.0.1
  • Patched version(s): 5.0.2

References

Could your website be exposed too?

SmartScanner can check your website for [email protected] contains malware after npm account takeover and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated September 15, 2025