Executive brief
The popular npm package 'color-string', used for parsing and generating CSS colors, was compromised following a phishing attack on a maintainer's account. A malicious version (2.1.1) was published containing code designed to intercept and redirect cryptocurrency transactions to an attacker's wallet. This affects applications that bundle this library for use in web browsers, potentially leading to the theft of digital assets from end-users.
Technical details
The npm package 'color-string' version 2.1.1 was found to contain embedded malicious code (CWE-506) following a successful phishing attack against the maintainer. The malware specifically targets browser environments and cryptocurrency wallets like MetaMask by deobfuscating a payload that replaces legitimate destination wallet addresses with attacker-controlled addresses during transactions. While server-side and CLI environments are unaffected, any browser-based bundles (created via Vite, Webpack, etc.) incorporating this version are compromised. The malicious version has been removed from the npm registry, and version 2.1.2 was released as a clean 'cache-busting' update.
Affected products
- Qix- color-string 2.1.1
Timeline
- 2025-09-08: exploited: Maintainer account compromised via phishing and malicious version 2.1.1 published.
- 2025-09-08: patched: npm removed the offending version from the registry.
- 2025-09-13: patched: Version 2.1.2 published to clear caches in private registries.
- 2025-09-15: advisory: GitHub Security Advisory published.
References
- https://github.com/Qix-/color-string/security/advisories/GHSA-286p-vc9p-p5qv
- https://github.com/debug-js/debug/issues/1005
- https://github.com/Qix-/color-string
- https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack
- https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
- https://www.ox.security/blog/npm-packages-compromised