Junglewise Threat Intelligence

CVE-2025-59162: color-convert npm package contains malware after account takeover

CVE-2025-59162 · Severity: medium · CVSS 4 · Published 2025-09-15

Vendors: npm.

Executive brief

color-convert is a widely-used JavaScript library for color conversion included in many web applications and development tools. Following an npm account compromise via phishing, version 3.1.1 was published with embedded malware designed to intercept and redirect cryptocurrency transactions from browser-based wallets like MetaMask. Applications using this library in web browsers may unknowingly serve malicious code to users.

Technical details

CWE-506: Embedded Malicious Code. The malware was injected into color-convert@3.1.1 after the npm publishing account was compromised through a phishing attack on 8 September 2025. The payload targets browser environments specifically, attempting to intercept and redirect cryptocurrency wallet transactions; server-side and CLI usage are unaffected. The attack vector is supply-chain compromise requiring no user interaction—any application bundling this library version for web delivery will inadvertently deliver the malicious code. Patches were released as version 3.1.2 on 13 September 2025; users must update, clear caches, and rebuild browser bundles from scratch to remove the embedded payload.

Affected products

  • npm color-convert 3.1.1

Timeline

  • 2025-09-08: exploited: npm account compromised via phishing; malware-laden version 3.1.1 published
  • 2025-09-13: patched: Version 3.1.2 released with malware removed
  • 2025-09-15: disclosed

References