Description
On 8 September 2025, the npm publishing account for color was taken over after a phishing attack. Version 5.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker’s own addresses from within browser environments.
Recommendation
Update the color package to the latest compatible version. Followings are version details:
- Affected version(s): = 5.0.1
- Patched version(s): 5.0.2
References
Could your website be exposed too?
SmartScanner can check your website for [email protected] contains malware after npm account takeover and gives you actionable findings to investigate.
Start a free scanRelated Issues
- [email protected] contains malware after npm account takeover - CVE-2025-59142
- [email protected] contains malware after npm account takeover - CVE-2025-59144
- SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover - CVE-2026-44648
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - CVE-2026-34751


