bluedoor data·Trust Centers API·bluedoor.sh

Home / Security updates / NPM Package Compromise – Advisory

NPM Package Compromise – Advisory

Security updates detail rendered from /security-updates/upd_8b5b1cb43c6072a5.

Overview

IDupd_8b5b1cb43c6072a5
CollectionSecurity Updates
ProviderTrustShare (TrustCloud / Kintent)
CompanyAtScale
URL-
Counts-
Updated-

Raw record

FieldValue
idupd_8b5b1cb43c6072a5
providerIdtrustshare
organizationIdorg_db273a5a9975ce7c
trustCenterIdtc_e18c73eb1ba73749
titleNPM Package Compromise – Advisory
typesecurity_advisory
messageOn September 18, 2025, security researchers reported a new supply-chain attack campaign against the NPM ecosystem, referred to as “S1ngularityNX / Shai-Hulud”, where multiple NPM packages were compromised and distributed with malicious payloads. Reference: Aikido Advisory Impact on AtScale We have reviewed the advisory and conducted a dependency review. Not observed anything related to “Shai-Hulud.” Verified the SBOM of both Container and Installer builds. Confirmed that no impacted packages are used in our product repositories.
publishedAt2025-09-23
gatedno
source
{
  "field": "trustshare/notifications[]"
}
company
{
  "id": "org_db273a5a9975ce7c",
  "name": "AtScale",
  "domains": [
    "atscale.trustshare.com"
  ]
}
trust_center
{
  "id": "tc_e18c73eb1ba73749",
  "name": "AtScale",
  "url": "https://atscale.trustshare.com",
  "host": "atscale.trustshare.com"
}
provider
{
  "id": "trustshare",
  "name": "TrustShare (TrustCloud / Kintent)"
}
links
{
  "self": "/v1/security-updates/upd_8b5b1cb43c6072a5",
  "company": "/v1/companies/org_db273a5a9975ce7c",
  "trust_center": "/v1/trust-centers/tc_e18c73eb1ba73749",
  "provider": "/v1/providers/trustshare"
}
Get this page with API

Rendered from the bluedoor Trust Centers API. Reproduce it:

GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_8b5b1cb43c6072a5JSON