Incident tracker · 25 Nov 2021

Are you exposed to the rc supply-chain (November 2021)?

Maintainer's npm token was compromised; attacker published malicious versions that ran a credential-stealing payload during install.

Confirmed-compromised packages1 package
npm
rccompromised: 1.2.9, 1.3.9, 2.3.9
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo