Executive brief
The color-name npm package, a widely-used JavaScript library for CSS color names, was compromised when its maintainer's npm account was taken over via phishing. Version 2.0.1 contains malicious code designed to intercept and redirect cryptocurrency transactions to attacker-controlled wallet addresses in browser environments. This poses a direct financial loss risk to applications using this package in web contexts, particularly those handling cryptocurrency transactions or using crypto wallets like MetaMask.
Technical details
This is a supply-chain attack involving account takeover and malware injection (CWE-506: Embedded Malicious Code). On 8 September 2025, the npm account for color-name was compromised after a phishing email spoofed npm's 2FA reset process. The attacker published version 2.0.1, functionally identical to the previous version but embedding obfuscated code that intercepts and replaces cryptocurrency wallet addresses with attacker-controlled addresses. The payload only executes in browser contexts (checking for `typeof window !== 'undefined'`), making server-side and CLI applications unaffected. The malware specifically targets cryptocurrency transactions and MetaMask-compatible wallets. npm removed the malicious package from its registry on 8 September; patched versions (2.0.2+) were released on 13 September. Users must update, purge node_modules, clear package manager caches, and rebuild browser bundles from scratch to eliminate risk.
Affected products
- npm color-name 2.0.1
Timeline
- 2025-09-08: exploited: npm account takeover via phishing; malicious version 2.0.1 published
- 2025-09-08: other: npm removed malicious package from registry
- 2025-09-13: patched: Patched version 2.0.2+ released to help cache-bust compromised versions
- 2025-09-15: advisory: Public advisory published (GHSA-5fvm-p68v-5wmh, CVE-2025-59145)
References
- https://github.com/colorjs/color-name/security/advisories/GHSA-5fvm-p68v-5wmh
- https://github.com/debug-js/debug/issues/1005
- https://github.com/colorjs/color-name
- https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack
- https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
- https://www.ox.security/blog/npm-packages-compromised