CVE-2025-59142 describes a supply chain attack where the color-string npm package (version 2.1.1) was compromised via a phishing attack on its publisher's account. This malicious version, functionally identical to its predecessor, included a malware payload designed to redirect cryptocurrency transactions within browser environments. The vulnerability primarily impacts web applications using color-string in a browser context, with local or server environments unaffected. The vulnerability carries a high CVSS score of 8.8, indicating a significant risk due to its network-based attack vector and low attack complexity. The potential impact is high integrity loss, as the malware aims to steal cryptocurrency, though it does not affect confidentiality or availability. While the compromised package was quickly removed from npm, and patched versions (2.1.2 and above) were released, there is no evidence of active exploitation in the wild, nor are there publicly available exploit tools. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Qix- | Color-String | = 2.1.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.