---
title: "color npm package compromised"
url: https://daily.dev/posts/color-npm-package-compromised-wgu7k5kd9
source_url: https://fasterthanli.me/articles/color-npm-package-compromised
type: article
source: "fasterthanli.me"
published: 2025-09-08T16:54:05.536Z
updated: 2025-09-09T16:49:34.992Z
tags: ["security", "javascript", "cyber", "npm"]
reading_time: 3
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# color npm package compromised

**[fasterthanli.me](https://daily.dev/sources/fasterthanli)** · 3 min read · 1 upvotes · 0 comments

## Summary

Josh Junon's npm account was compromised via a fake 2FA reset email, leading to backdoored versions of popular packages including 'color' (32M weekly downloads) and 'chalk'. The malicious payload appears designed to target crypto websites in browsers rather than server environments. The attack required multiple steps to be effective: upgrading dependencies, using them on the frontend, deploying to production, and users making transactions. Sindre Sorhus quickly republished chalk without the backdoor.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://fasterthanli.me/articles/color-npm-package-compromised>

---

Tags: [#security](https://daily.dev/tags/security), [#javascript](https://daily.dev/tags/javascript), [#cyber](https://daily.dev/tags/cyber), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/color-npm-package-compromised-wgu7k5kd9)
