Bryce Boe's Avatar

Bryce Boe

@bryceboe.com.bsky.social

Dad, husband, software engineer @ Netflix, and educator.

30 Followers  |  45 Following  |  2 Posts  |  Joined: 13.07.2023  |  1.7133

Latest posts by bryceboe.com on Bluesky

Preview
Popular Tinycolor npm Package Compromised in Supply Chain At... Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers

🚨 Malicious update to @ctrl/tinycolor on npm is part of an active supply chain attack hitting 40+ packages across multiple maintainers. Audit & remove affected versions.

Our analysis of the malware: socket.dev/blog/tinycol... #NodeJS #JavaScript

15.09.2025 23:23 β€” πŸ‘ 30    πŸ” 20    πŸ’¬ 0    πŸ“Œ 14

Honestly serious: JUST DON'T UPDATE PACKAGES RIGHT NOW.

It is unclear to me yet, but this is looking pretty wide spread. Better be safe than sorry, just go touch some grass.

15.09.2025 22:29 β€” πŸ‘ 75    πŸ” 40    πŸ’¬ 4    πŸ“Œ 6
Preview
scttcper - Packages - Socket Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.

Oh, and all of these. socket.dev/npm/user/sct...

15.09.2025 22:35 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
farfromrefuge - Packages - Socket Socket fights vulnerabilities and provides visibility, defense-in-depth, and proactive supply chain protection for JavaScript, Python, and Go dependencies.

These are likely all compromised as well: socket.dev/npm/user/far...

15.09.2025 22:38 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Do not update to @ctrl/tinycolor@4.1.2. It has malware that is currently live on npm.

15.09.2025 22:15 β€” πŸ‘ 22    πŸ” 4    πŸ’¬ 1    πŸ“Œ 2

Thanks!

13.07.2023 03:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I'm excited to finally be on #bluesky. Now I need to curate my feeds.

13.07.2023 00:47 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@bryceboe.com is following 20 prominent accounts