Home / Security updates / Security Advisory: Shai-Hulud NPM Supply Chain Attack
Security Advisory: Shai-Hulud NPM Supply Chain Attack
Security updates detail rendered from /security-updates/upd_0d5b2b1617c14fc6.
Overview
| ID | upd_0d5b2b1617c14fc6 |
| Collection | Security Updates |
| Provider | SafeBase |
| Company | OutSystems |
| URL | - |
| Counts | - |
| Updated | - |
Raw record
| Field | Value |
|---|---|
| id | upd_0d5b2b1617c14fc6 |
| providerId | safebase |
| organizationId | org_0decd878c3bf1d15 |
| trustCenterId | tc_c5550fe1a987d713 |
| title | Security Advisory: Shai-Hulud NPM Supply Chain Attack |
| message | We are aware of the ongoing Shai-Hulud self-propagating supply chain attack impacting compromised NPM packages, as reported in the security community. Following a thorough review of our product lifecycle and software supply chain, we can confirm that the OutSystems Platform is not impacted. The impacted NPM packages and versions are not part of the OutSystems Platform by default. However, customers may have the ability to introduce custom code or integrations that leverage these NPM packages. We recommend that customers review their own environments and validate whether any of the compromised NPM packages are in use. Our Security and Engineering teams will continue to monitor developments closely and provide updates on this page as needed. |
| url | - |
| publishedAt | 2025-09-18 |
| source | {
"field": "statuspage/public/compliance-update",
"category": "vulnerabilities"
} |
| company | {
"id": "org_0decd878c3bf1d15",
"name": "OutSystems",
"domains": [
"security.outsystems.com",
"outsystems.com"
]
} |
| trust_center | {
"id": "tc_c5550fe1a987d713",
"name": "OutSystems",
"url": "https://security.outsystems.com",
"host": "security.outsystems.com"
} |
| provider | {
"id": "safebase",
"name": "SafeBase"
} |
| links | {
"self": "/v1/security-updates/upd_0d5b2b1617c14fc6",
"company": "/v1/companies/org_0decd878c3bf1d15",
"trust_center": "/v1/trust-centers/tc_c5550fe1a987d713",
"provider": "/v1/providers/safebase"
} |
Get this page with API
Rendered from the bluedoor Trust Centers API. Reproduce it:
GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_0d5b2b1617c14fc6JSON