Settings

Theme

Malicious NPM Versions (chalk, debug, strip-ANSI) Found in September 2025 Attack

blog.firstpoint.com.tr

3 points by cosmodev 4 months ago · 1 comment

Reader

cosmodevOP 4 months ago

On September 8–9, 2025, a major NPM supply chain attack compromised packages like chalk, debug, and strip-ansi. We built an open source tool (guard-deps) to scan repos and remediate malicious versions. This post summarizes the attack details and provides a full list of compromised versions.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection