@cyberhub/trust-colors
v1.0.63
Published
Security Trust Report: [email protected] — 47/100 (C, caution). Security incident detected. Maintainer risk, supply chain analysis from 8 security databases.
Maintainers
Readme
Security Trust Report: colors
[email protected]: 47/100 | Grade: C | Tier: CAUTION (confidence: ±3)
Data verified on 2026-04-02 from 8 security databases.
TL;DR
- Security incident detected — compromised via account takeover/sabotage
- Consider switching to chalk (Most popular terminal color library)
- Action required: Review flags below and upgrade or replace this package
⚠️ Security Incident Background
In January 2022, maintainer marak deliberately sabotaged the package by adding an infinite loop, causing applications to print garbage text. This was a protest against large corporations using open-source without compensation.
Score Breakdown
Maintainer Trust: █████████░░░░░░░░░░░ 44/100
Package Health: ██████████████████░░ 88/100
Supply Chain: ██░░░░░░░░░░░░░░░░░░ 10/100
Community: █████████░░░░░░░░░░░ 47/100Why this score?
- Maintainer Trust is 44 because: single maintainer (bus factor risk)
- Supply Chain is 10 because: 1 security incident(s) in breach database, in breach database
- Community is 47 because: no public GitHub repo linked (may be private or on another platform)
⚠️ Security Incident
This package was compromised via account takeover/sabotage (no CVE assigned). See Security Incident Background above for details.
Key Risk Flags
- 🔴 CRITICAL: Package name "colors" is 2 edit(s) from popular "cors"
- 🔴 CRITICAL: HISTORICAL BREACH: Maintainer sabotaged with infinite loop (2022)
- 🔴 CRITICAL: 1 CRITICAL security incident from breach database (no CVE assigned)
- 🔴 CRITICAL: Maintainer "marak" has history of package sabotage
🛠️ What Should You Do?
Immediate:
- 📌 Pin to known-safe version: 1.4.0 (before sabotage)
- 🔄 Or replace with chalk — Most popular terminal color library
- 📖 Review the security incident above
Always: Pin version, run pkgtrust scan in CI, monitor at nrupak.com/trust/colors
🔄 Safer Alternatives
| Package | Why | Trust Report | |---------|-----|-------------| | chalk | Most popular terminal color library | View score | | picocolors | Tiny, fast, zero dependencies | View score | | kleur | Lightweight alternative | View score |
Maintainers
- ⛔ marak — COMPROMISED: Deliberately sabotaged colors and faker (2022)
Methodology: 18+ signals across 4 categories (Maintainer 35%, Package 25%, Supply Chain 25%, Community 15%). Full scoring docs →
Check your project: npm i -g @cyberhub/pkgtrust && pkgtrust scan colors — CLI docs
Data Sources: GitHub Advisories · OSV.dev · npm audit · Snyk · Socket.dev · npms.io · Bundlephobia · deps.dev
Report by pkgtrust · Dashboard · Compare · CLI
This is an automated security report. Not affiliated with the colors team. Updated 2026-04-02.
