Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Qix

#29849de 53,632
8.8CVSS total
Vulnerabilidades · 1
PT-2025-37744
8.8
2025-09-08
Npm · Color-String · CVE-2025-59142
**Name of the Vulnerable Software and Affected Versions** color-string version 2.1.1 **Description** The npm publishing account for color-string was compromised following a phishing attack. Version 2.1.1 was published with a malicious payload designed to redirect cryptocurrency transactions within browser environments. The malware specifically targets cryptocurrency transactions and wallets such as MetaMask. Local, server, and command-line environments are not affected. **Recommendations** Update to version 2.1.2. Completely remove the `node modules` directory. Clean the package manager's global cache. Rebuild any browser bundles from scratch. Purge the compromised versions from any private registry caches.