PT-2025-37760 · Npm · Color-Name

Informatic

·

Published

2025-09-08

·

Updated

2026-06-15

·

CVE-2025-59145

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Red
Name of the Vulnerable Software and Affected Versions color-name versions prior to 2.0.2
Description An npm publishing account for color-name was taken over following a phishing attack. Version 2.0.1 was published with a malware payload designed to redirect cryptocurrency transactions to the attacker's addresses within browser environments. Local, server, and command-line environments are not affected. The malware specifically targets cryptocurrency transactions and wallets such as MetaMask.
Recommendations Update to version 2.0.2. Completely remove the node modules directory. Clean the package manager's global cache. Rebuild any browser bundles from scratch. Purge the compromised versions from any private registries or registry mirrors.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07577
CVE-2025-59145
GHSA-5FVM-P68V-5WMH
GHSA-M99C-CFWW-CXQX
MAL-2025-46972

Affected Products

Color-Name