See the full list of npm packages compromised in the "Shai-Hulud supply chain attack – Sep 2025" [View compromised packages].
@libp2p/floodsub vulnerabilities
libp2p-floodsub, also known as pubsub-flood or just dumbsub, this implementation of pubsub focused on delivering an API for Publish/Subscribe, but with no CastTree Forming (it just floods the network).