See the full list of npm packages compromised in the "SHA1-Hulud npm supply chain incident – Nov 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applications| VULNERABILITY | AFFECTS | TYPE | PUBLISHED |
|---|---|---|---|
| @freeday-ai/webchat=2025.11.2-4.7.32.11335=2025.11.2-4.9.17.4962=2025.11.2-4.7.37.6205=2025.11.2-4.9.1.11380 | npm | 27 Nov 2025 |
| @medusajs/medusa-oas-cli=2.11.4-preview-20251124060135=2.11.4-preview-20251124032825=2.11.4-preview-20251124090208 | npm | 27 Nov 2025 |
| @medusajs/medusa=2.11.4-preview-20251124090208=2.11.4-preview-20251124060135 | npm | 27 Nov 2025 |
| @medusajs/analytics-posthog=2.11.4-preview-20251124060135=2.11.4-preview-20251124090208 | npm | 27 Nov 2025 |
| tianocore/edk2[edk2-stable202211,edk2-stable202502) | Unmanaged (C/C++) | 27 Nov 2025 |
| pretix[,2025.7.2)[2025.8.0,2025.8.1)[2025.9.0,2025.9.1) | pip | 27 Nov 2025 |
| bitcoin-lib-js* | npm | 27 Nov 2025 |
| bip40* | npm | 27 Nov 2025 |
| bitcoin-main-lib* | npm | 27 Nov 2025 |
| org.apache.hive:hive-standalone-metastore-server[,4.2.0) | Maven | 27 Nov 2025 |
| distrotech/cups-filters[,2.0.1) | Unmanaged (C/C++) | 27 Nov 2025 |
| wireshark[4.6.0,4.6.1) | Unmanaged (C/C++) | 27 Nov 2025 |
| spotipy[,2.25.2) | pip | 27 Nov 2025 |
| tutor[0,] | pip | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata[,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| better-auth>=1.3.34 <1.4.0 | npm | 27 Nov 2025 |
| suricata[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| @angular/common<19.2.16>=20.0.0-next.0 <20.3.14>=21.0.0-next.0 <21.0.1 | npm | 27 Nov 2025 |
| suricata[,7.0.13)[8.0.0,8.0.2) | Unmanaged (C/C++) | 27 Nov 2025 |
| suricata-htp>=8.0.0 <8.0.2 | Cargo | 27 Nov 2025 |
| redaxo/source<5.20.1 | Composer | 27 Nov 2025 |
| redaxo/source<5.20.1 | Composer | 27 Nov 2025 |
| mistral-dashboard[,14.0.1) | pip | 27 Nov 2025 |
| nanomq/NanoNNG[,0.24.3) | Unmanaged (C/C++) | 27 Nov 2025 |
| tinyproxy/tinyproxy[0,] | Unmanaged (C/C++) | 27 Nov 2025 |
| org.opensearch:opensearch[,2.19.4)[3.0.0-alpha1,3.3.0) | Maven | 27 Nov 2025 |
| willitmerge* | npm | 27 Nov 2025 |