Malicious NPM Versions (chalk, debug, strip-ANSI) Found in September 2025 Attack
3 cosmodev 1 9/10/2025, 11:38:30 AM blog.firstpoint.com.tr ↗
Comments (1)
cosmodev · 12h ago
On September 8–9, 2025, a major NPM supply chain attack compromised packages like chalk, debug, and strip-ansi.
We built an open source tool (guard-deps) to scan repos and remediate malicious versions.
This post summarizes the attack details and provides a full list of compromised versions.