OP article says: > The incident was discovered by @franky47, who promptly notified the community through a GitHub issue.
Points to this, which does look like the first mention.
https://github.com/scttcper/tinycolor/issues/256