About npm hack
#7263
Replies: 2 comments 1 reply
-
Well, do you have links to the packages that were hacked? |
Beta Was this translation helpful? Give feedback.
0 replies
-
Here are more details about the hack: https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the?r=133gq&utm_campaign=post&utm_medium=reddit&triedRedirect=true These packages are compromised:
Regards |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I would like to ask whether MeshCentral or its dependencies could be affected by the recent npm supply chain compromise (Sept 2025), where popular packages such as chalk, debug, ansi-styles, color-name, color-convert, strip-ansi, chalk-template, and backslash were tampered with.
Since MeshCentral is built on Node.js, is there any risk that a compromised version of these packages might have been pulled in during installation or update?
If yes, what versions are safe to use?
Do you recommend administrators reinstall MeshCentral with a clean set of dependencies to be sure?
Thank you for clarifying!
Beta Was this translation helpful? Give feedback.
All reactions