Description
On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker’s own addresses from within browser environments.
Recommendation
Update the color-string package to the latest compatible version. Followings are version details:
- Affected version(s): = 2.1.1
- Patched version(s): 2.1.2
References
- GHSA-286p-vc9p-p5qv
- socket.dev
- www.aikido.dev
- www.ox.security
- CVE-2025-59142
- CWE-506
- CAPEC-310
- OWASP 2021-A6
Related Issues
- [email protected] contains malware after npm account takeover - CVE-2025-59143
- [email protected] contains malware after npm account takeover - CVE-2025-59144
- SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover - CVE-2026-44648
- Regular Expression Denial of Service (ReDOS) - color-string - CVE-2021-29060
You might also like:
- Tags:
- npm
- color-string
Anything's wrong? Let us know Last updated on September 15, 2025


