See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
devenvx vulnerabilities
DevEnvx is a zero-install CLI tool that sets up full development environments (Python, Java, C++, and more) on Windows using one simple command. No downloads, no browser — just run and code.