TechFlow, September 16 — According to the Socket Research Team, the popular npm package @ctrl/tinycolor (with 2.2 million weekly downloads) has been maliciously updated, becoming part of a large-scale supply chain attack affecting over 40 packages.
Affected packages include angulartics2@14.1.2, @ctrl/tinycolor@4.1.1/4.1.2, ngx-color@10.0.2, and more than 40 others. Socket advises users to immediately uninstall or pin to known secure versions, audit environments where affected versions were installed, and rotate npm tokens and other exposed credentials.




