Описание
color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct
Ссылки
EPSS
Процентиль: 26%
0.00091
Низкий
Дефекты
CWE-506
Связанные уязвимости
github
5 месяцев назад
color-name@2.0.1 contains malware after npm account takeover
EPSS
Процентиль: 26%
0.00091
Низкий
Дефекты
CWE-506