QID 45522
QID 45522: Npm Multiple Malicious Packages Detected (colors.js and faker.js)
The developer of these libraries intentionally introduced an infinite loop that bricked thousands of projects that depend on 'colors' and 'faker.
Affected Packages
colors 1.4.0
faker 5.5.3
QID Detection Logic (Authenticated) :
This checks for installed package name and node in NPM .
NPM projects should ensure they are not using an unsafe version. Downgrading to an earlier version of colors (e.g. 1.4.0) and faker (e.g. 5.5.3) is one solution.
Solution
Vendor References
- colors -
www.npmjs.com/package/colors/v/1.4.0 - faker -
www.npmjs.com/package/faker/v/5.5.3 - liberty -
www.npmjs.com/package/liberty/v/0.3.1
CVEs related to QID 45522
Software Advisories
| Advisory ID | Software | Component | Link |
|---|