See the full list of npm packages compromised in the "Shai-Hulud supply chain attack – Sep 2025" [View compromised packages].
Find out if you have vulnerabilities that put you at risk
Test your applicationsVULNERABILITY | AFFECTS | TYPE | PUBLISHED |
---|---|---|---|
| libssh[0.6.0,0.11.3) | Unmanaged (C/C++) | 23 Sept 2025 |
| mapserver[,8.4.1) | Unmanaged (C/C++) | 23 Sept 2025 |
| libtiff[,4.7.1-rc1) | Unmanaged (C/C++) | 23 Sept 2025 |
| asterisk[,18.26.3)[20.15.0,20.15.1)[21.10.0,21.10.1)[22.5.0,22.5.1) | Unmanaged (C/C++) | 23 Sept 2025 |
| pjuhasz/JSON-SIMD[,1.07) | Unmanaged (C/C++) | 23 Sept 2025 |
| dnsdist[1.9.0,1.9.11)[2.0.0,2.0.1) | Unmanaged (C/C++) | 23 Sept 2025 |
| axboe/fio[0,] | Unmanaged (C/C++) | 23 Sept 2025 |
| axboe/fio[0,) | Unmanaged (C/C++) | 23 Sept 2025 |
| appneta/tcpreplay[,4.5.2) | Unmanaged (C/C++) | 23 Sept 2025 |
| ghostscript[,10.06.0rc1) | Unmanaged (C/C++) | 22 Sept 2025 |
| ghostscript[,10.06.0rc1) | Unmanaged (C/C++) | 22 Sept 2025 |
| ghostscript[,10.06.0rc1) | Unmanaged (C/C++) | 22 Sept 2025 |
| open5gs/open5gs[,2.7.6) | Unmanaged (C/C++) | 22 Sept 2025 |
| proftpd/proftpd[1.3.3c,1.3.3d) | Unmanaged (C/C++) | 22 Sept 2025 |
| postgresql[11.20,13.22)[14.0,14.19)[15.0,15.14)[16.0,16.10)[17.0,17.6) | Unmanaged (C/C++) | 22 Sept 2025 |
| zephyrproject-rtos/zephyr[0,] | Unmanaged (C/C++) | 22 Sept 2025 |
| zephyrproject-rtos/zephyr[0,] | Unmanaged (C/C++) | 22 Sept 2025 |
| zephyrproject-rtos/zephyr[,4.2.0-rc2) | Unmanaged (C/C++) | 22 Sept 2025 |
| zephyrproject-rtos/zephyr[0,] | Unmanaged (C/C++) | 21 Sept 2025 |
| qemu-project/qemu[10.0.0-rc0,10.1.0-rc4) | Unmanaged (C/C++) | 21 Sept 2025 |
| chromium[,140.0.7339.127) | Unmanaged (C/C++) | 18 Sept 2025 |
| chromium[,140.0.7339.127) | Unmanaged (C/C++) | 18 Sept 2025 |
| bytecodealliance/wasm-micro-runtime[,2.4.2) | Unmanaged (C/C++) | 18 Sept 2025 |
| ufoaiorg/ufoai[,2.3.1) | Unmanaged (C/C++) | 18 Sept 2025 |
| chromium[,140.0.7339.185) | Unmanaged (C/C++) | 18 Sept 2025 |
| ffmpeg[,8.0) | Unmanaged (C/C++) | 18 Sept 2025 |
| wireshark[,4.4.9) | Unmanaged (C/C++) | 18 Sept 2025 |
| ImageMagick/ImageMagick[,6.9.13-29)[7.0.7-9, 7.1.2-3) | Unmanaged (C/C++) | 17 Sept 2025 |
| thunderbird[,143.0) | Unmanaged (C/C++) | 17 Sept 2025 |
| Firefox[,143.0) | Unmanaged (C/C++) | 17 Sept 2025 |