<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2349  Information about the NPM Software Supply Chain Attack Shai-Hulud</title><link>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2349  Information about the NPM Software Supply Chain Attack Shai-Hulud</title><link>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud</link><pubDate>Wed, 03 Dec 2025 20:24:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ca1f867b-874a-4b9d-b0df-c72e1b34c84d</guid><dc:creator>Appian Community</dc:creator><comments>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud#comments</comments><description>Current Revision posted to Appian Knowledge Base by Appian Community on 12/3/2025 8:24:52 PM&lt;br /&gt;
&lt;p&gt;On 09-Sep-2025, multiple npm packages were compromised as part of a software supply chain attack after the accounts for official maintainers of the npm package manager were compromised.&lt;/p&gt;
&lt;p&gt;Appian has investigated this incident and, as of 09-10-2025, determined that it is not impacted as none of the affected package versions listed below are utilized. We will continue to monitor the situation and provide updates as appropriate.&lt;/p&gt;
&lt;p&gt;Updates&lt;br /&gt;01-Dec-2025: Appian is continuously monitoring the exploited package list and determined to still not be impacted&lt;/p&gt;
&lt;p&gt;Supporting Documentation&lt;br /&gt;https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html&lt;br /&gt;https://www.upwind.io/feed/shai-hulud-2-npm-supply-chain-worm-attack&lt;br /&gt;https://docs.mend.io/wsk/msc-customer-reference-sheet-24-nov-2025&lt;/p&gt;
&lt;p&gt;Investigated Package Versions&lt;br /&gt;Appian has reviewed all currently known impacted packages&lt;br /&gt;Affected Versions&lt;br /&gt;This article applies to all supported versions of Appian.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;Last reviewed: Dec 3, 2025&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-2349  Information about the NPM Software Supply Chain Attack Shai-Hulud</title><link>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud/revision/2</link><pubDate>Wed, 03 Dec 2025 20:21:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ca1f867b-874a-4b9d-b0df-c72e1b34c84d</guid><dc:creator>Kaushal Patel</dc:creator><comments>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud#comments</comments><description>Revision 2 posted to Appian Knowledge Base by Kaushal Patel on 12/3/2025 8:21:59 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 09-Sep-2025, multiple npm packages were compromised as part of a software supply chain attack after the accounts for official maintainers of the npm package manager were compromised.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this incident and, as of 09-10-2025, determined that it is not impacted as none of the affected package versions listed below are utilized. We will continue to monitor the situation and provide updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Updates&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span&gt;01-Dec-2025: Appian is continuously monitoring the exploited package list and determined to still not be impacted&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Supporting Documentation&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;span style="font-weight:400;"&gt;&lt;a id="" href="https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html"&gt;https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html&lt;/a&gt;&lt;a href="https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.upwind.io/feed/shai-hulud-2-npm-supply-chain-worm-attack"&gt;https://www.upwind.io/feed/shai-hulud-2-npm-supply-chain-worm-attack&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://docs.mend.io/wsk/msc-customer-reference-sheet-24-nov-2025"&gt;https://docs.mend.io/wsk/msc-customer-reference-sheet-24-nov-2025&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;span&gt;Investigated Package Versions&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Appian has reviewed all currently known impacted packages&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&lt;span&gt;&amp;nbsp;Dec 3&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-2349  Information about the NPM Software Supply Chain Attack Shai-Hulud</title><link>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud/revision/3</link><pubDate>Wed, 03 Dec 2025 20:21:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ca1f867b-874a-4b9d-b0df-c72e1b34c84d</guid><dc:creator>Appian Community</dc:creator><comments>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud#comments</comments><description>Revision 3 posted to Appian Knowledge Base by Appian Community on 12/3/2025 8:21:59 PM&lt;br /&gt;
This content is under review.&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>KB-2349  Information about the NPM Software Supply Chain Attack</title><link>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud/revision/1</link><pubDate>Wed, 10 Sep 2025 21:44:35 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:ca1f867b-874a-4b9d-b0df-c72e1b34c84d</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3706/kb-2349-information-about-the-npm-software-supply-chain-attack-shai-hulud#comments</comments><description>Revision 1 posted to Appian Knowledge Base by pauline.delacruz on 9/10/2025 9:44:35 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 09-Sep-2025, multiple npm packages were compromised as part of a software supply chain attack after the accounts for official maintainers of the npm package manager were compromised.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated this incident and, as of 09-10-2025, determined that it is not impacted as none of the affected package versions listed below are utilized. We will continue to monitor the situation and provide updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span&gt;Supporting Documentation&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html"&gt;&lt;span style="font-weight:400;"&gt;https://thehackernews.com/2025/09/20-popular-npm-packages-with-2-billion.html&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Investigated Package Versions&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span&gt;Ansi-regex v6.2.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Ansi-styles v6.2.2&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Backslash v0.2.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Chalk v5.6.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Chalk-template v1.1.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Color-convert v3.1.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Color-name v2.0.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Color-string v2.1.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Debug v4.4.2&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Error-ex v1.3.3&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Has-ansi v6.0.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Is-arrayish v0.3.3&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Proto-tinker-wc v1.8.7&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Supports-hyperlinks v4.1.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Simple-swizzle v0.2.3&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Slice-ansi v7.1.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Strip-ansi v7.1.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Supports-color v10.2.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Wrap-ansi v9.0.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;coveops/abi v2.0.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;duckdb/duckdb-wasm v1.29.2&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;duckdb/node-api v1.3.3&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;duckdb/node-bindings v1.3.3&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Duckdb v1.3.3&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Prebid v10.9.1&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Prebid v10.9.2&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span&gt;Prebid-universal-creative v1.17.3&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed: &lt;/span&gt;&lt;span style="font-weight:400;"&gt;Sep 10, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>