See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applications| VULNERABILITY | AFFECTS | TYPE | PUBLISHED |
|---|---|---|---|
| @accordproject/markdown-cli=0.16.20-20251124101628 | npm | 27 Nov 2025 |
| @axinom/mosaic-cli=0.52.0-rc.2 | npm | 27 Nov 2025 |
| inmaa-map=1.0.0-beta.4 | npm | 27 Nov 2025 |
| @devx-commerce/plugin-discounts=2.0.0-beta.1 | npm | 27 Nov 2025 |
| @eventcatalog/generator-asyncapi=5.1.0 | npm | 27 Nov 2025 |
| @kong/spec-renderer=1.101.10-pr.747.ed2920a.0 | npm | 27 Nov 2025 |
| @flowfuse/flowfuse=2.24.2-375f5e6-202511240929.0 | npm | 27 Nov 2025 |
| @opentermsarchive/engine=10.1.0=10.0.1 | npm | 27 Nov 2025 |
| @freeday-ai/webchat=2025.11.2-4.7.32.11335=2025.11.2-4.9.17.4962=2025.11.2-4.7.37.6205=2025.11.2-4.9.1.11380 | npm | 27 Nov 2025 |
| @medusajs/medusa-oas-cli=2.11.4-preview-20251124060135=2.11.4-preview-20251124032825=2.11.4-preview-20251124090208 | npm | 27 Nov 2025 |
| @medusajs/medusa=2.11.4-preview-20251124090208=2.11.4-preview-20251124060135 | npm | 27 Nov 2025 |
| @medusajs/analytics-posthog=2.11.4-preview-20251124060135=2.11.4-preview-20251124090208 | npm | 27 Nov 2025 |
| tianocore/edk2[edk2-stable202211,edk2-stable202502) | Unmanaged (C/C++) | 27 Nov 2025 |
| pretix[,2025.7.2)[2025.8.0,2025.8.1)[2025.9.0,2025.9.1) | pip | 27 Nov 2025 |
| bitcoin-lib-js* | npm | 27 Nov 2025 |
| bip40* | npm | 27 Nov 2025 |
| bitcoin-main-lib* | npm | 27 Nov 2025 |
| org.apache.hive:hive-standalone-metastore-server[,4.2.0) | Maven | 27 Nov 2025 |
| distrotech/cups-filters[,2.0.1) | Unmanaged (C/C++) | 27 Nov 2025 |
| wireshark[4.6.0,4.6.1) | Unmanaged (C/C++) | 27 Nov 2025 |
| spotipy[,2.25.2) | pip | 27 Nov 2025 |
| tutor[0,] | pip | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata[,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| better-auth>=1.3.34 <1.4.0 | npm | 27 Nov 2025 |
| suricata[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| @angular/common<19.2.16>=20.0.0-next.0 <20.3.14>=21.0.0-next.0 <21.0.1 | npm | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |