GitLab discovers widespread npm supply chain attackYet another week; yet another supply chain attack...#blog#data#git#javascript#nodejs#packaging#research#security#supplychain#typescript·about.gitlab.com·Nov 25, 2025GitLab discovers widespread npm supply chain attack
ctrl/tinycolor and 40+ NPM Packages Compromised - StepSecurityA pretty impressive and concerning compromise of a lot of JavaScript (and by extension TypeScript) packages.#hacking#javascript#nodejs#security#supplychain#typescript·stepsecurity.io·Sep 16, 2025ctrl/tinycolor and 40+ NPM Packages Compromised - StepSecurity