See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
@capacitor/device vulnerabilities
The Device API exposes internal information about the device, such as the model and operating system version, along with user information such as unique ids.