See the full list of npm packages compromised in the "Shai-Hulud supply chain attack – Sep 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applicationsVULNERABILITY | AFFECTS | TYPE | PUBLISHED |
---|---|---|---|
| stedolan/jq[1.8.0,1.8.1) | Unmanaged (C/C++) | 7 Jul 2025 |
| gimp[,3.1.2) | Unmanaged (C/C++) | 7 Jul 2025 |
| gimp[,3.0.0) | Unmanaged (C/C++) | 7 Jul 2025 |
| ESP32Async/ESPAsyncWebServer[,3.7.9) | Unmanaged (C/C++) | 7 Jul 2025 |
| icinga/icinga2[, 2.12.12)[2.13.0, 2.13.12)[2.14.0, 2.14.6) | Unmanaged (C/C++) | 7 Jul 2025 |
| notepad-plus-plus/notepad-plus-plus[,8.8.2) | Unmanaged (C/C++) | 7 Jul 2025 |
| grub2[0,] | Unmanaged (C/C++) | 6 Jul 2025 |
| nbdkit/nbdkit[1.21.16,1.43.10) | Unmanaged (C/C++) | 6 Jul 2025 |
| nbdkit/nbdkit[1.11.10,1.43.10) | Unmanaged (C/C++) | 6 Jul 2025 |
| qt/qtbase[5.0.0-alpha1,6.7.2)[6.8.0-beta1,6.9.1) | Unmanaged (C/C++) | 6 Jul 2025 |
| coreutils[7.2,] | Unmanaged (C/C++) | 6 Jul 2025 |
| qt/qtbase[6.8.0, 6.10.0-beta1) | Unmanaged (C/C++) | 6 Jul 2025 |
| uYanki/board-stm32f103rc-berial[0,] | Unmanaged (C/C++) | 6 Jul 2025 |
| unicode-org/icu[0,] | Unmanaged (C/C++) | 4 Jul 2025 |
| gimp[,2.99.6) | Unmanaged (C/C++) | 4 Jul 2025 |
| gimp[,3.0.0) | Unmanaged (C/C++) | 4 Jul 2025 |
| gimp[,3.0.0) | Unmanaged (C/C++) | 4 Jul 2025 |
| taglib[,2.0beta) | Unmanaged (C/C++) | 4 Jul 2025 |
| libssh[,0.11.2) | Unmanaged (C/C++) | 4 Jul 2025 |
| libssh[,0.11.2) | Unmanaged (C/C++) | 4 Jul 2025 |
| libssh[,0.11.2) | Unmanaged (C/C++) | 4 Jul 2025 |
| djvu[,3.5.29) | Unmanaged (C/C++) | 4 Jul 2025 |
| mickem/nscp[0,] | Unmanaged (C/C++) | 4 Jul 2025 |
| mickem/nscp[,0.8.0) | Unmanaged (C/C++) | 4 Jul 2025 |
| poppler[,25.06.0) | Unmanaged (C/C++) | 4 Jul 2025 |
| spiderlabs/modsecurity[2.9.8, 2.9.11) | Unmanaged (C/C++) | 3 Jul 2025 |
| sudo[1.9.14,1.9.17p1) | Unmanaged (C/C++) | 2 Jul 2025 |
| sudo[1.8.8,1.9.17p1) | Unmanaged (C/C++) | 2 Jul 2025 |
| chromium[,138.0.7204.92) | Unmanaged (C/C++) | 2 Jul 2025 |
| vslavik/poedit[2.0,3.6.3) | Unmanaged (C/C++) | 2 Jul 2025 |