Incident tracker · 8 Jan 2022

Are you exposed to the colors.js / faker.js maintainer sabotage (January 2022)?

Marak Squires intentionally pushed broken releases that print zalgo text and infinite-loop, breaking thousands of downstream builds.

Confirmed-compromised packages2 packages
npm
colorscompromised: 1.4.1, 1.4.2, 1.4.44-liberty-2
npm
fakercompromised: 6.6.6
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo