QID 376712
Date Published: 2022-07-07
QID 376712: Npm Multiple Malicious Packages Detected (colors.js and faker.js)
The developer of these libraries intentionally introduced an infinite loop that bricked thousands of projects that depend on 'colors' and 'faker.
Affected Packages
colors 1.4.44-liberty-2, 1.4.1, and 1.4.2
faker 6.6.6
QID Detection Logic (Authenticated) :
This checks for installed package name and node in NPM .
NPM projects should ensure they are not using an unsafe version. Downgrading to an earlier version of colors (e.g. 1.4.0) and faker (e.g. 5.5.3) is one solution.
Solution
Vendor References
CVEs related to QID 376712
Software Advisories
| Advisory ID | Software | Component | Link |
|---|