-
Cryptocurrencies
-
Exchanges
-
Media
Cryptocurrencies: 23843
Exchanges: 115
Market Cap: $$3.94T
24h Vol: $140.97B
Dominance: BTC: 58.3% ETH: 13.8%
ETH Gas: 29 Gwei
All languages
Cryptocurrencies
Exchanges
Media
Share
According to a Scam Sniffer warning, the NPM package "@ctrl/tinycolor," with 2.2 million weekly downloads, has been infected with a malicious version. This stealer runs during the npm postinstall process and uses the legitimate tool TruffleHog to scan and exfiltrate sensitive data. Approximately 40 dependent packages have been affected. Users are advised to immediately check whether they have installed the affected version, suspend updates, and lock in a secure version.