Incident tracker · 22 Oct 2021

Are you exposed to the ua-parser-js supply-chain (October 2021)?

Maintainer's npm credentials were compromised; published versions installed a crypto-miner plus a password-stealing payload on Windows hosts.

Confirmed-compromised packages1 package
npm
ua-parser-jscompromised: 0.7.29, 0.8.0, 1.0.0
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo