Dependency health Supply-chain news

Supply-chain news

The incidents behind a package’s reputation. Read what happened, which releases were affected, and what the original investigators found.

Reviewed reports · last reviewed 2026-09-05. This is a selected incident record, not an exhaustive live threat feed. A past compromise does not establish that the current release is compromised.

· npm

Chalk, debug and other npm packages carried wallet-targeting code ↗

Aikido reported compromised releases across a widely used group of npm packages. The injected browser code attempted to redirect cryptocurrency transactions to attacker-controlled destinations.

Affected versions: Affected releases differ by package; see the original report.

Packages: chalk · debug · ansi-styles · supports-color · strip-ansi · ansi-regex · color-convert · color-name · wrap-ansi · slice-ansi · is-arrayish · error-ex · color-string · simple-swizzle · has-ansi · supports-hyperlinks · chalk-template · backslash

Source: Aikido Security

· npm

Nx publishes its s1ngularity compromise post-mortem ↗

Nx described how a GitHub Actions injection exposed a publishing token and enabled malicious releases that collected sensitive files. Its response included trusted publishing and manual release approval.

Affected versions: See Nx’s linked advisory for the package-specific affected versions.

Packages: nx

Source: Nx maintainers

High-profile vulnerabilities and your dependencies

Astra’s top-ten article ↗ collects historical CVEs from 2020–2022. It is not a live ranking or the OWASP Top 10. The mapping below explains which entries relate to package identities we check.

An identity match is a reason to investigate, not confirmation that your installed release is vulnerable. Manifest checks do not establish runtime configuration or resolve every transitive dependency.

VulnerabilityProduct / package relationship
ZeroLogon
CVE-2020-1472 ↗
Windows / Netlogon

Host and domain-controller assessment required.

Outside package-only scan coverage
Log4Shell
CVE-2021-44228 ↗
Apache Log4j Core

Applies to specific log4j-core releases, not log4j-api alone. Check resolved and bundled dependencies against Apache’s affected-version ranges.

org.apache.logging.log4j:log4j-core
ICMAD
CVE-2022-22536 ↗
SAP NetWeaver / related SAP services

Requires SAP product and deployment inventory.

Outside package-only scan coverage
ProxyLogon
CVE-2021-26855 ↗
Microsoft Exchange Server

Check the Exchange deployment; a NuGet package name cannot establish exposure.

Outside package-only scan coverage
Spring4Shell
CVE-2022-22965 ↗
Spring Framework

Historical affected branches include 5.3.0–5.3.17 and 5.2.19 and earlier. Exploitability depends on runtime and deployment; consult Spring’s advisory.

org.springframework:spring-webmvc · org.springframework:spring-webflux · org.springframework:spring-beans
Confluence RCE
CVE-2022-26134 ↗
Atlassian Confluence

Requires Confluence Server or Data Center version inventory.

Outside package-only scan coverage
vCenter RCE
CVE-2021-21972 ↗
VMware vCenter Server

Requires infrastructure product and version inventory.

Outside package-only scan coverage
Chrome use-after-free
CVE-2022-0609 ↗
Google Chrome

Check the installed browser; JavaScript package names do not identify its version.

Outside package-only scan coverage
Follina
CVE-2022-30190 ↗
Windows MSDT

Requires Windows patch and configuration assessment.

Outside package-only scan coverage
PetitPotam
CVE-2021-36942 ↗
Windows LSA / EFSRPC

Requires Windows and domain configuration assessment.

Outside package-only scan coverage

Runtime vulnerabilities on OpenCVE

Browse CVEs by vendor and product. Runtime CVEs do not automatically apply to every package in that ecosystem; verify affected versions and configurations.

News & advisory sources

Follow these publishers and official advisories for broader coverage. RSS links open their feeds; articles are not automatically imported into the reviewed reports above. Feedspot is a directory for discovering feeds.