@ctrl/tinycolornpm
- latest 4.2.0
- licence MIT
- stars 614
- checked yesterday
- registry ↗
- repository ↗
Signals · last 1 check
State history 1
| When | Change |
|---|---|
| 2026-09-03 | first verdict: coasting |
Supply-chain history 1
-
malicious release 2025-09
Compromised by the self-replicating Shai-Hulud worm, which stole developer credentials and republished itself through victims’ own packages.
Cleaned and republished; the worm hit hundreds of packages before being contained.
Source: Shai-Hulud npm worm reporting, September 2025. History, not a warning about today — the verdict above is about maintenance now.
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/npm/@ctrl/tinycolor)
Watch it
Get told when @ctrl/tinycolor changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.