Malicious Payload in Color-Name JSON Package by npm
CVE-2025-59145
What is CVE-2025-59145?
A supply chain attack occurred on the color-name package, leading to the distribution of a malicious version (2.0.1). This version was released after the npm publishing account was compromised through phishing, embedding malware specifically aimed at redirecting cryptocurrency transactions. Users who included this package in their browser environments via script tags or bundling tools (like Babel, Rollup, or Next.js) may have unwittingly exposed themselves to data theft involving wallets like MetaMask. Though npm took immediate action by removing the harmful package, users are strongly advised to upgrade to version 2.0.2, delete their node_modules directory, and purge any cached versions from npm organizations or mirrors to ensure their environments are secure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
color-name = 2.0.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
