CVE-2025-59145
color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected.
Leer descripción completaMostrar menos
If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. See references below for more information on the payload. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from npm proper. On 13 September, the package owner published new patch versions to help cache-bust those using private registries who might still have the compromised version cached. Users should update to the latest patch version, completely remove their node_modules directory, clean their package manager's global cache, and rebuild any browser bundles from scratch. Those operating private registries or registry mirrors should purge the offending versions from any caches. This issue is resolved in 2.0.2.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.55%
- Percentil entre todas las CVEs puntuadas: 44
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access60 %
Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (5)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-506
Referencias
- https://github.com/colorjs/color-name/security/advisories/GHSA-5fvm-p68v-5wmh
- https://github.com/debug-js/debug/issues/1005
- https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack
- https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
- https://www.ox.security/blog/npm-packages-compromised
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-59145",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-59145",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-09-15T20:39:50.044627Z"
}
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.8,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
"exploitMaturity": "ATTACKED",
"providerUrgency": "RED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "colorjs",
"product": "color-name",
"versions": [
{
"status": "affected",
"version": "= 2.0.1"
}
]
}
]
}
],
"published": "2025-09-15T21:15:36.633",
"references": [
{
"url": "https://github.com/colorjs/color-name/security/advisories/GHSA-5fvm-p68v-5wmh",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/debug-js/debug/issues/1005",
"source": "security-advisories@github.com"
},
{
"url": "https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack",
"source": "security-advisories@github.com"
},
{
"url": "https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised",
"source": "security-advisories@github.com"
},
{
"url": "https://www.ox.security/blog/npm-packages-compromised",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-506"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the attacker's own addresses from within browser environments. Local environments, server environments, command line applications, etc. are not affected. If the package was used in a browser context (e.g. a direct <script> inclusion, or via a bundling tool such as Babel, Rollup, Vite, Next.js, etc.) there is a chance the malware still exists and such bundles will need to be rebuilt. The malware seemingly only targets cryptocurrency transactions and wallets such as MetaMask. See references below for more information on the payload. npm removed the offending package from the registry over the course of the day on 8 September, preventing further downloads from npm proper. On 13 September, the package owner published new patch versions to help cache-bust those using private registries who might still have the compromised version cached. Users should update to the latest patch version, completely remove their node_modules directory, clean their package manager's global cache, and rebuild any browser bundles from scratch. Those operating private registries or registry mirrors should purge the offending versions from any caches. This issue is resolved in 2.0.2."
},
{
"lang": "es",
"value": "color-name es un JSON con nombres de colores CSS. El 8 de septiembre de 2025, una cuenta de publicación de npm para color-name fue tomada después de un ataque de phishing. La versión 2.0.1 fue publicada, funcionalmente idéntica a la versión de parche anterior, pero con una carga útil de malware añadida que intentaba redirigir transacciones de criptomonedas a las propias direcciones del atacante desde entornos de navegador. Entornos locales, entornos de servidor, aplicaciones de línea de comandos, etc. no están afectados. Si el paquete fue utilizado en un contexto de navegador (p. ej., una inclusión directa de <script>, o a través de una herramienta de empaquetado como Babel, Rollup, Vite, Next.js, etc.) existe la posibilidad de que el malware aún exista y dichos paquetes deberán ser reconstruidos. El malware aparentemente solo apunta a transacciones de criptomonedas y billeteras como MetaMask. Consulte las referencias a continuación para obtener más información sobre la carga útil. npm eliminó el paquete ofensivo del registro a lo largo del día del 8 de septiembre, evitando descargas adicionales desde npm propiamente dicho. El 13 de septiembre, el propietario del paquete publicó nuevas versiones de parche para ayudar a invalidar la caché de aquellos que usan registros privados y que aún podrían tener la versión comprometida en caché. Los usuarios deben actualizar a la última versión de parche, eliminar completamente su directorio node_modules, limpiar la caché global de su gestor de paquetes y reconstruir cualquier paquete de navegador desde cero. Aquellos que operan registros privados o espejos de registro deben purgar las versiones ofensivas de cualquier caché. Este problema se resuelve en 2.0.2."
}
],
"lastModified": "2026-09-30T23:10:00.237",
"sourceIdentifier": "security-advisories@github.com"
}