Junglewise Threat Intelligence

CVE-2025-59143: npm color library malware injection via account takeover

CVE-2025-59143 · Severity: medium · CVSS 4 · Published 2025-09-15

Vendors: npm.

Executive brief

The npm package "color", a widely-used JavaScript library for color manipulation, was compromised after the maintainer's account was hijacked through phishing. Version 5.0.1 was published with embedded malware designed to intercept and redirect cryptocurrency transactions to attacker-controlled wallets in browser environments. This supply-chain compromise could expose users of web applications relying on this library to cryptocurrency theft if they interact with blockchain applications or cryptocurrency wallets.

Technical details

This is a supply-chain attack delivering embedded malicious code (CWE-506) via a legitimate npm package. The attacker gained access to the npm publishing account through a successful phishing campaign and released version 5.0.1 containing a malware payload that targets cryptocurrency transactions and wallet integrations (e.g., MetaMask) within browser execution environments. The attack vector is network-based and requires no user interaction beyond using the compromised library version in a web application context; server-side, CLI, and local environments are not affected. npm removed the malicious version from the registry on 8 September 2025, and patched version 5.0.2 was released on 13 September 2025. Users must update to 5.0.2 or later, completely rebuild node_modules and browser bundles, and clear package manager caches.

Affected products

  • npm color 5.0.1

Timeline

  • 2025-09-15: disclosed: GHSA-qrmh-qg46-72pp and CVE-2025-59143 published
  • 2025-09-08: exploited: npm account takeover via phishing; malicious version 5.0.1 published
  • 2025-09-13: patched: Patched version 5.0.2 released

References