tops-bmad
Version:
CLI tool to install BMAD workflow files into any project with integrated Shai-Hulud 2.0 security scanning
2,509 lines • 115 kB
JSON
{
"version": "2.0.0",
"lastUpdated": "2025-12-02T14:33:33.863Z",
"dataSource": {
"url": "https://github.com/DataDog/indicators-of-compromise/tree/main/shai-hulud-2.0",
"description": "Consolidated IOCs from multiple security vendors",
"sources": [
"datadog",
"helixguard",
"koi",
"reversinglabs",
"socketdev",
"stepsecurity",
"wiz"
],
"fetchedAt": "2025-12-02T14:33:33.863Z"
},
"attackInfo": {
"name": "Shai-Hulud 2.0",
"alias": "The Second Coming",
"firstDetected": "2025-11-24T03:16:00Z",
"description": "Self-replicating npm worm targeting credential theft and supply chain compromise. Spread to 30,000+ repositories and 790+ npm packages within 72 hours."
},
"indicators": {
"maliciousFiles": [
"setup_bun.js",
"bun_environment.js",
"cloud.json",
"contents.json",
"environment.json",
"truffleSecrets.json",
"actionsSecrets.json",
"trufflehog_output.json"
],
"maliciousWorkflows": [
".github/workflows/discussion.yaml",
".github/workflows/discussion.yml",
".github/workflows/formatter_*.yml"
],
"fileHashes": {
"setup_bun.js": {
"sha1": "d1829b4708126dcc7bea7437c04d1f10eacd4a16",
"sha256": "a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a"
},
"bun_environment.js": {
"sha1": "d60ec97eea19fffb4809bc35b91033b52490ca11",
"sha256": [
"62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0",
"cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd",
"f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068",
"f1df4896244500671eb4aa63ebb48ea11cee196fafaa0e9874e17b24ac053c02",
"9d59fd0bcc14b671079824c704575f201b74276238dc07a9c12a93a84195648a",
"e0250076c1d2ac38777ea8f542431daf61fcbaab0ca9c196614b28065ef5b918"
]
}
},
"gitHubIndicators": {
"runnerName": "SHA1HULUD",
"repoDescription": "Sha1-Hulud: The Second Coming.",
"repoNamePattern": "[0-9a-z]{18}",
"workflowTrigger": "on: discussion"
},
"runnerPaths": [
"$HOME/.dev-env/",
"actions-runner-linux-x64-2.330.0.tar.gz"
],
"credentialPaths": [
".config/gcloud/application_default_credentials.json",
".npmrc"
],
"primaryInfectionVectors": [
"@postman/tunnel-agent@0.6.7",
"posthog-node",
"@asyncapi/specs@6.8.3"
],
"mavenPackages": [
"org.mvnpm:posthog-node:4.18.1"
]
},
"acknowledgements": {
"securityResearchers": [
{
"org": "Wiz",
"github": "wiz-sec"
},
{
"org": "Datadog Security Labs",
"github": "DataDog"
},
{
"org": "Aikido Security",
"github": "AikidoSec"
},
{
"org": "Postman",
"github": "postmanlabs"
},
{
"org": "PostHog",
"github": "PostHog"
},
{
"org": "HelixGuard",
"github": "helixguard"
}
]
},
"packages": [
{
"name": "02-echo",
"severity": "critical",
"affectedVersions": [
"0.0.7"
]
},
{
"name": "@accordproject/concerto-analysis",
"severity": "critical",
"affectedVersions": [
"3.24.1"
]
},
{
"name": "@accordproject/concerto-linter",
"severity": "critical",
"affectedVersions": [
"3.24.1"
]
},
{
"name": "@accordproject/concerto-linter-default-ruleset",
"severity": "critical",
"affectedVersions": [
"3.24.1"
]
},
{
"name": "@accordproject/concerto-metamodel",
"severity": "critical",
"affectedVersions": [
"3.12.5"
]
},
{
"name": "@accordproject/concerto-types",
"severity": "critical",
"affectedVersions": [
"3.24.1"
]
},
{
"name": "@accordproject/markdown-it-cicero",
"severity": "critical",
"affectedVersions": [
"0.16.26"
]
},
{
"name": "@accordproject/template-engine",
"severity": "critical",
"affectedVersions": [
"2.7.2"
]
},
{
"name": "@actbase/css-to-react-native-transform",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@actbase/native",
"severity": "critical",
"affectedVersions": [
"0.1.32"
]
},
{
"name": "@actbase/node-server",
"severity": "critical",
"affectedVersions": [
"1.1.19"
]
},
{
"name": "@actbase/react-absolute",
"severity": "critical",
"affectedVersions": [
"0.8.3"
]
},
{
"name": "@actbase/react-daum-postcode",
"severity": "critical",
"affectedVersions": [
"1.0.5"
]
},
{
"name": "@actbase/react-kakaosdk",
"severity": "critical",
"affectedVersions": [
"0.9.27"
]
},
{
"name": "@actbase/react-native-actionsheet",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@actbase/react-native-devtools",
"severity": "critical",
"affectedVersions": [
"0.1.3"
]
},
{
"name": "@actbase/react-native-fast-image",
"severity": "critical",
"affectedVersions": [
"8.5.13"
]
},
{
"name": "@actbase/react-native-kakao-channel",
"severity": "critical",
"affectedVersions": [
"1.0.2"
]
},
{
"name": "@actbase/react-native-kakao-navi",
"severity": "critical",
"affectedVersions": [
"2.0.4"
]
},
{
"name": "@actbase/react-native-less-transformer",
"severity": "critical",
"affectedVersions": [
"1.0.6"
]
},
{
"name": "@actbase/react-native-naver-login",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@actbase/react-native-simple-video",
"severity": "critical",
"affectedVersions": [
"1.0.13"
]
},
{
"name": "@actbase/react-native-tiktok",
"severity": "critical",
"affectedVersions": [
"1.1.3"
]
},
{
"name": "@afetcan/api",
"severity": "critical",
"affectedVersions": [
"0.0.13"
]
},
{
"name": "@afetcan/storage",
"severity": "critical",
"affectedVersions": [
"0.0.27"
]
},
{
"name": "@alaan/s2s-auth",
"severity": "critical",
"affectedVersions": [
"2.0.3"
]
},
{
"name": "@alexadark/amadeus-api",
"severity": "critical",
"affectedVersions": [
"1.0.4"
]
},
{
"name": "@alexadark/gatsby-theme-events",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@alexadark/gatsby-theme-wordpress-blog",
"severity": "critical",
"affectedVersions": [
"2.0.1"
]
},
{
"name": "@alexadark/reusable-functions",
"severity": "critical",
"affectedVersions": [
"1.5.1"
]
},
{
"name": "@alexcolls/nuxt-socket.io",
"severity": "critical",
"affectedVersions": [
"0.0.7",
"0.0.8"
]
},
{
"name": "@alexcolls/nuxt-ux",
"severity": "critical",
"affectedVersions": [
"0.6.1",
"0.6.2"
]
},
{
"name": "@antstackio/eslint-config-antstack",
"severity": "critical",
"affectedVersions": [
"0.0.3"
]
},
{
"name": "@antstackio/express-graphql-proxy",
"severity": "critical",
"affectedVersions": [
"0.2.8"
]
},
{
"name": "@antstackio/graphql-body-parser",
"severity": "critical",
"affectedVersions": [
"0.1.1"
]
},
{
"name": "@antstackio/json-to-graphql",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@antstackio/shelbysam",
"severity": "critical",
"affectedVersions": [
"1.1.7"
]
},
{
"name": "@aryanhussain/my-angular-lib",
"severity": "critical",
"affectedVersions": [
"0.0.23"
]
},
{
"name": "@asyncapi/avro-schema-parser",
"severity": "critical",
"affectedVersions": [
"3.0.25",
"3.0.26"
]
},
{
"name": "@asyncapi/bundler",
"severity": "critical",
"affectedVersions": [
"0.6.5",
"0.6.6"
]
},
{
"name": "@asyncapi/cli",
"severity": "critical",
"affectedVersions": [
"4.1.2",
"4.1.3"
]
},
{
"name": "@asyncapi/converter",
"severity": "critical",
"affectedVersions": [
"1.6.3",
"1.6.4"
]
},
{
"name": "@asyncapi/diff",
"severity": "critical",
"affectedVersions": [
"0.5.1",
"0.5.2"
]
},
{
"name": "@asyncapi/dotnet-rabbitmq-template",
"severity": "critical",
"affectedVersions": [
"1.0.1",
"1.0.2"
]
},
{
"name": "@asyncapi/edavisualiser",
"severity": "critical",
"affectedVersions": [
"1.2.1",
"1.2.2"
]
},
{
"name": "@asyncapi/generator",
"severity": "critical",
"affectedVersions": [
"2.8.5",
"2.8.6"
]
},
{
"name": "@asyncapi/generator-components",
"severity": "critical",
"affectedVersions": [
"0.3.2",
"0.3.3"
]
},
{
"name": "@asyncapi/generator-helpers",
"severity": "critical",
"affectedVersions": [
"0.2.1",
"0.2.2"
]
},
{
"name": "@asyncapi/generator-react-sdk",
"severity": "critical",
"affectedVersions": [
"1.1.4",
"1.1.5"
]
},
{
"name": "@asyncapi/go-watermill-template",
"severity": "critical",
"affectedVersions": [
"0.2.76",
"0.2.77"
]
},
{
"name": "@asyncapi/html-template",
"severity": "critical",
"affectedVersions": [
"3.3.2",
"3.3.3"
]
},
{
"name": "@asyncapi/java-spring-cloud-stream-template",
"severity": "critical",
"affectedVersions": [
"0.13.5",
"0.13.6"
]
},
{
"name": "@asyncapi/java-spring-template",
"severity": "critical",
"affectedVersions": [
"1.6.1",
"1.6.2"
]
},
{
"name": "@asyncapi/java-template",
"severity": "critical",
"affectedVersions": [
"0.3.5",
"0.3.6"
]
},
{
"name": "@asyncapi/keeper",
"severity": "critical",
"affectedVersions": [
"0.0.2",
"0.0.3"
]
},
{
"name": "@asyncapi/markdown-template",
"severity": "critical",
"affectedVersions": [
"1.6.8",
"1.6.9"
]
},
{
"name": "@asyncapi/modelina",
"severity": "critical",
"affectedVersions": [
"5.10.2",
"5.10.3"
]
},
{
"name": "@asyncapi/modelina-cli",
"severity": "critical",
"affectedVersions": [
"5.10.2",
"5.10.3"
]
},
{
"name": "@asyncapi/multi-parser",
"severity": "critical",
"affectedVersions": [
"2.2.1",
"2.2.2"
]
},
{
"name": "@asyncapi/nodejs-template",
"severity": "critical",
"affectedVersions": [
"3.0.5",
"3.0.6"
]
},
{
"name": "@asyncapi/nodejs-ws-template",
"severity": "critical",
"affectedVersions": [
"0.10.1",
"0.10.2"
]
},
{
"name": "@asyncapi/nunjucks-filters",
"severity": "critical",
"affectedVersions": [
"2.1.1",
"2.1.2"
]
},
{
"name": "@asyncapi/openapi-schema-parser",
"severity": "critical",
"affectedVersions": [
"3.0.25",
"3.0.26"
]
},
{
"name": "@asyncapi/optimizer",
"severity": "critical",
"affectedVersions": [
"1.0.5",
"1.0.6"
]
},
{
"name": "@asyncapi/parser",
"severity": "critical",
"affectedVersions": [
"3.4.1",
"3.4.2"
]
},
{
"name": "@asyncapi/php-template",
"severity": "critical",
"affectedVersions": [
"0.1.1",
"0.1.2"
]
},
{
"name": "@asyncapi/problem",
"severity": "critical",
"affectedVersions": [
"1.0.1",
"1.0.2"
]
},
{
"name": "@asyncapi/protobuf-schema-parser",
"severity": "critical",
"affectedVersions": [
"3.5.2",
"3.5.3",
"3.6.1"
]
},
{
"name": "@asyncapi/python-paho-template",
"severity": "critical",
"affectedVersions": [
"0.2.14",
"0.2.15"
]
},
{
"name": "@asyncapi/react-component",
"severity": "critical",
"affectedVersions": [
"2.6.6",
"2.6.7"
]
},
{
"name": "@asyncapi/server-api",
"severity": "critical",
"affectedVersions": [
"0.16.24",
"0.16.25"
]
},
{
"name": "@asyncapi/specs",
"severity": "critical",
"affectedVersions": [
"6.10.1",
"6.8.2",
"6.8.3",
"6.9.1"
]
},
{
"name": "@asyncapi/studio",
"severity": "critical",
"affectedVersions": [
"1.0.2",
"1.0.3"
]
},
{
"name": "@asyncapi/web-component",
"severity": "critical",
"affectedVersions": [
"2.6.6",
"2.6.7"
]
},
{
"name": "@bdkinc/knex-ibmi",
"severity": "critical",
"affectedVersions": [
"0.5.7"
]
},
{
"name": "@browserbasehq/bb9",
"severity": "critical",
"affectedVersions": [
"1.2.21"
]
},
{
"name": "@browserbasehq/director-ai",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@browserbasehq/mcp",
"severity": "critical",
"affectedVersions": [
"2.1.1"
]
},
{
"name": "@browserbasehq/mcp-server-browserbase",
"severity": "critical",
"affectedVersions": [
"2.4.2"
]
},
{
"name": "@browserbasehq/sdk-functions",
"severity": "critical",
"affectedVersions": [
"0.0.4"
]
},
{
"name": "@browserbasehq/stagehand",
"severity": "critical",
"affectedVersions": [
"3.0.4"
]
},
{
"name": "@browserbasehq/stagehand-docs",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@caretive/caret-cli",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@chtijs/eslint-config",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@clausehq/flows-step-httprequest",
"severity": "critical",
"affectedVersions": [
"0.1.14"
]
},
{
"name": "@clausehq/flows-step-jsontoxml",
"severity": "critical",
"affectedVersions": [
"0.1.14"
]
},
{
"name": "@clausehq/flows-step-mqtt",
"severity": "critical",
"affectedVersions": [
"0.1.14"
]
},
{
"name": "@clausehq/flows-step-sendgridemail",
"severity": "critical",
"affectedVersions": [
"0.1.14"
]
},
{
"name": "@clausehq/flows-step-taskscreateurl",
"severity": "critical",
"affectedVersions": [
"0.1.14"
]
},
{
"name": "@cllbk/ghl",
"severity": "critical",
"affectedVersions": [
"1.3.1"
]
},
{
"name": "@commute/bloom",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@commute/market-data",
"severity": "critical",
"affectedVersions": [
"1.0.2"
]
},
{
"name": "@commute/market-data-chartjs",
"severity": "critical",
"affectedVersions": [
"2.3.1"
]
},
{
"name": "@dev-blinq/ai-qa-logic",
"severity": "critical",
"affectedVersions": [
"1.0.19"
]
},
{
"name": "@dev-blinq/blinqioclient",
"severity": "critical",
"affectedVersions": [
"1.0.21"
]
},
{
"name": "@dev-blinq/cucumber-js",
"severity": "critical",
"affectedVersions": [
"1.0.131"
]
},
{
"name": "@dev-blinq/cucumber_client",
"severity": "critical",
"affectedVersions": [
"1.0.1637-dev",
"1.0.738",
"1.0.739"
]
},
{
"name": "@dev-blinq/ui-systems",
"severity": "critical",
"affectedVersions": [
"1.0.93"
]
},
{
"name": "@ensdomains/address-encoder",
"severity": "critical",
"affectedVersions": [
"1.1.5"
]
},
{
"name": "@ensdomains/blacklist",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@ensdomains/buffer",
"severity": "critical",
"affectedVersions": [
"0.1.2"
]
},
{
"name": "@ensdomains/ccip-read-cf-worker",
"severity": "critical",
"affectedVersions": [
"0.0.4"
]
},
{
"name": "@ensdomains/ccip-read-dns-gateway",
"severity": "critical",
"affectedVersions": [
"0.1.1"
]
},
{
"name": "@ensdomains/ccip-read-router",
"severity": "critical",
"affectedVersions": [
"0.0.7"
]
},
{
"name": "@ensdomains/ccip-read-worker-viem",
"severity": "critical",
"affectedVersions": [
"0.0.4"
]
},
{
"name": "@ensdomains/content-hash",
"severity": "critical",
"affectedVersions": [
"3.0.1"
]
},
{
"name": "@ensdomains/curvearithmetics",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@ensdomains/cypress-metamask",
"severity": "critical",
"affectedVersions": [
"1.2.1"
]
},
{
"name": "@ensdomains/dnsprovejs",
"severity": "critical",
"affectedVersions": [
"0.5.3"
]
},
{
"name": "@ensdomains/dnssec-oracle-anchors",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@ensdomains/dnssecoraclejs",
"severity": "critical",
"affectedVersions": [
"0.2.9"
]
},
{
"name": "@ensdomains/durin",
"severity": "critical",
"affectedVersions": [
"0.1.2"
]
},
{
"name": "@ensdomains/durin-middleware",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@ensdomains/ens-archived-contracts",
"severity": "critical",
"affectedVersions": [
"0.0.3"
]
},
{
"name": "@ensdomains/ens-avatar",
"severity": "critical",
"affectedVersions": [
"1.0.4"
]
},
{
"name": "@ensdomains/ens-contracts",
"severity": "critical",
"affectedVersions": [
"1.6.1"
]
},
{
"name": "@ensdomains/ens-test-env",
"severity": "critical",
"affectedVersions": [
"1.0.2"
]
},
{
"name": "@ensdomains/ens-validation",
"severity": "critical",
"affectedVersions": [
"0.1.1"
]
},
{
"name": "@ensdomains/ensjs",
"severity": "critical",
"affectedVersions": [
"4.0.3"
]
},
{
"name": "@ensdomains/ensjs-react",
"severity": "critical",
"affectedVersions": [
"0.0.5"
]
},
{
"name": "@ensdomains/eth-ens-namehash",
"severity": "critical",
"affectedVersions": [
"2.0.16"
]
},
{
"name": "@ensdomains/hackathon-registrar",
"severity": "critical",
"affectedVersions": [
"1.0.5"
]
},
{
"name": "@ensdomains/hardhat-chai-matchers-viem",
"severity": "critical",
"affectedVersions": [
"0.1.15"
]
},
{
"name": "@ensdomains/hardhat-toolbox-viem-extended",
"severity": "critical",
"affectedVersions": [
"0.0.6"
]
},
{
"name": "@ensdomains/mock",
"severity": "critical",
"affectedVersions": [
"2.1.52"
]
},
{
"name": "@ensdomains/name-wrapper",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@ensdomains/offchain-resolver-contracts",
"severity": "critical",
"affectedVersions": [
"0.2.2"
]
},
{
"name": "@ensdomains/op-resolver-contracts",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@ensdomains/react-ens-address",
"severity": "critical",
"affectedVersions": [
"0.0.32"
]
},
{
"name": "@ensdomains/renewal",
"severity": "critical",
"affectedVersions": [
"0.0.13"
]
},
{
"name": "@ensdomains/renewal-widget",
"severity": "critical",
"affectedVersions": [
"0.1.10"
]
},
{
"name": "@ensdomains/reverse-records",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@ensdomains/server-analytics",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@ensdomains/solsha1",
"severity": "critical",
"affectedVersions": [
"0.0.4"
]
},
{
"name": "@ensdomains/subdomain-registrar",
"severity": "critical",
"affectedVersions": [
"0.2.4"
]
},
{
"name": "@ensdomains/test-utils",
"severity": "critical",
"affectedVersions": [
"1.3.1"
]
},
{
"name": "@ensdomains/thorin",
"severity": "critical",
"affectedVersions": [
"0.6.51"
]
},
{
"name": "@ensdomains/ui",
"severity": "critical",
"affectedVersions": [
"3.4.6"
]
},
{
"name": "@ensdomains/unicode-confusables",
"severity": "critical",
"affectedVersions": [
"0.1.1"
]
},
{
"name": "@ensdomains/unruggable-gateways",
"severity": "critical",
"affectedVersions": [
"0.0.3"
]
},
{
"name": "@ensdomains/vite-plugin-i18next-loader",
"severity": "critical",
"affectedVersions": [
"4.0.4"
]
},
{
"name": "@ensdomains/web3modal",
"severity": "critical",
"affectedVersions": [
"1.10.2"
]
},
{
"name": "@everreal/react-charts",
"severity": "critical",
"affectedVersions": [
"2.0.1",
"2.0.2"
]
},
{
"name": "@everreal/validate-esmoduleinterop-imports",
"severity": "critical",
"affectedVersions": [
"1.4.4",
"1.4.5"
]
},
{
"name": "@everreal/web-analytics",
"severity": "critical",
"affectedVersions": [
"0.0.1",
"0.0.2"
]
},
{
"name": "@faq-component/core",
"severity": "critical",
"affectedVersions": [
"0.0.4"
]
},
{
"name": "@faq-component/react",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@fishingbooker/browser-sync-plugin",
"severity": "critical",
"affectedVersions": [
"1.0.5"
]
},
{
"name": "@fishingbooker/react-loader",
"severity": "critical",
"affectedVersions": [
"1.0.7"
]
},
{
"name": "@fishingbooker/react-pagination",
"severity": "critical",
"affectedVersions": [
"2.0.6"
]
},
{
"name": "@fishingbooker/react-raty",
"severity": "critical",
"affectedVersions": [
"2.0.1"
]
},
{
"name": "@fishingbooker/react-swiper",
"severity": "critical",
"affectedVersions": [
"0.1.5"
]
},
{
"name": "@hapheus/n8n-nodes-pgp",
"severity": "critical",
"affectedVersions": [
"1.5.1"
]
},
{
"name": "@hover-design/core",
"severity": "critical",
"affectedVersions": [
"0.0.1"
]
},
{
"name": "@hover-design/react",
"severity": "critical",
"affectedVersions": [
"0.2.1"
]
},
{
"name": "@huntersofbook/auth-vue",
"severity": "critical",
"affectedVersions": [
"0.4.2"
]
},
{
"name": "@huntersofbook/core",
"severity": "critical",
"affectedVersions": [
"0.5.1"
]
},
{
"name": "@huntersofbook/core-nuxt",
"severity": "critical",
"affectedVersions": [
"0.4.2"
]
},
{
"name": "@huntersofbook/form-naiveui",
"severity": "critical",
"affectedVersions": [
"0.5.1"
]
},
{
"name": "@huntersofbook/i18n",
"severity": "critical",
"affectedVersions": [
"0.8.2"
]
},
{
"name": "@huntersofbook/ui",
"severity": "critical",
"affectedVersions": [
"0.5.1"
]
},
{
"name": "@hyperlook/telemetry-sdk",
"severity": "critical",
"affectedVersions": [
"1.0.19"
]
},
{
"name": "@ifelsedeveloper/protocol-contracts-svm-idl",
"severity": "critical",
"affectedVersions": [
"0.1.2",
"0.1.3"
]
},
{
"name": "@ifings/design-system",
"severity": "critical",
"affectedVersions": [
"4.9.2"
]
},
{
"name": "@ifings/metatron3",
"severity": "critical",
"affectedVersions": [
"0.1.5"
]
},
{
"name": "@jayeshsadhwani/telemetry-sdk",
"severity": "critical",
"affectedVersions": [
"1.0.14"
]
},
{
"name": "@kvytech/cli",
"severity": "critical",
"affectedVersions": [
"0.0.7"
]
},
{
"name": "@kvytech/components",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@kvytech/habbit-e2e-test",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@kvytech/medusa-plugin-announcement",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@kvytech/medusa-plugin-management",
"severity": "critical",
"affectedVersions": [
"0.0.5"
]
},
{
"name": "@kvytech/medusa-plugin-newsletter",
"severity": "critical",
"affectedVersions": [
"0.0.5"
]
},
{
"name": "@kvytech/medusa-plugin-product-reviews",
"severity": "critical",
"affectedVersions": [
"0.0.9"
]
},
{
"name": "@kvytech/medusa-plugin-promotion",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@kvytech/web",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@lessondesk/api-client",
"severity": "critical",
"affectedVersions": [
"9.12.2",
"9.12.3"
]
},
{
"name": "@lessondesk/babel-preset",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@lessondesk/electron-group-api-client",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@lessondesk/eslint-config",
"severity": "critical",
"affectedVersions": [
"1.4.2"
]
},
{
"name": "@lessondesk/material-icons",
"severity": "critical",
"affectedVersions": [
"1.0.3"
]
},
{
"name": "@lessondesk/react-table-context",
"severity": "critical",
"affectedVersions": [
"2.0.4"
]
},
{
"name": "@lessondesk/schoolbus",
"severity": "critical",
"affectedVersions": [
"5.2.2",
"5.2.3"
]
},
{
"name": "@livecms/live-edit",
"severity": "critical",
"affectedVersions": [
"0.0.32"
]
},
{
"name": "@livecms/nuxt-live-edit",
"severity": "critical",
"affectedVersions": [
"1.9.2"
]
},
{
"name": "@lokeswari-satyanarayanan/rn-zustand-expo-template",
"severity": "critical",
"affectedVersions": [
"1.0.9"
]
},
{
"name": "@louisle2/core",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@louisle2/cortex-js",
"severity": "critical",
"affectedVersions": [
"0.1.6"
]
},
{
"name": "@lpdjs/firestore-repo-service",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@lui-ui/lui-nuxt",
"severity": "critical",
"affectedVersions": [
"0.1.1"
]
},
{
"name": "@lui-ui/lui-tailwindcss",
"severity": "critical",
"affectedVersions": [
"0.1.2"
]
},
{
"name": "@lui-ui/lui-vue",
"severity": "critical",
"affectedVersions": [
"1.0.13"
]
},
{
"name": "@markvivanco/app-version-checker",
"severity": "critical",
"affectedVersions": [
"1.0.1",
"1.0.2"
]
},
{
"name": "@mcp-use/cli",
"severity": "critical",
"affectedVersions": [
"2.2.6",
"2.2.7"
]
},
{
"name": "@mcp-use/inspector",
"severity": "critical",
"affectedVersions": [
"0.6.2",
"0.6.3"
]
},
{
"name": "@mcp-use/mcp-use",
"severity": "critical",
"affectedVersions": [
"1.0.1",
"1.0.2"
]
},
{
"name": "@micado-digital/stadtmarketing-kufstein-external",
"severity": "critical",
"affectedVersions": [
"1.9.1"
]
},
{
"name": "@mizzle-dev/orm",
"severity": "critical",
"affectedVersions": [
"0.0.2"
]
},
{
"name": "@mparpaillon/connector-parse",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@mparpaillon/imagesloaded",
"severity": "critical",
"affectedVersions": [
"4.1.2"
]
},
{
"name": "@mparpaillon/page",
"severity": "critical",
"affectedVersions": [
"1.0.1"
]
},
{
"name": "@ntnx/passport-wso2",
"severity": "critical",
"affectedVersions": [
"0.0.3"
]
},
{
"name": "@ntnx/t",
"severity": "critical",
"affectedVersions": [
"0.0.101"
]
},
{
"name": "@oku-ui/accordion",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/alert-dialog",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/arrow",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/aspect-ratio",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/avatar",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/checkbox",
"severity": "critical",
"affectedVersions": [
"0.6.3"
]
},
{
"name": "@oku-ui/collapsible",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/collection",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/dialog",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/direction",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/dismissable-layer",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/focus-guards",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/focus-scope",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/hover-card",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/label",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/menu",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/motion",
"severity": "critical",
"affectedVersions": [
"0.4.4"
]
},
{
"name": "@oku-ui/motion-nuxt",
"severity": "critical",
"affectedVersions": [
"0.2.2"
]
},
{
"name": "@oku-ui/popover",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/popper",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/portal",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/presence",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/primitive",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/primitives",
"severity": "critical",
"affectedVersions": [
"0.7.9"
]
},
{
"name": "@oku-ui/primitives-nuxt",
"severity": "critical",
"affectedVersions": [
"0.3.1"
]
},
{
"name": "@oku-ui/progress",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/provide",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/radio-group",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/roving-focus",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/scroll-area",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/separator",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/slider",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/slot",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/switch",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/tabs",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/toast",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/toggle",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/toggle-group",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/toolbar",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/tooltip",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/use-composable",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/utils",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@oku-ui/visually-hidden",
"severity": "critical",
"affectedVersions": [
"0.6.2"
]
},
{
"name": "@orbitgtbelgium/mapbox-gl-draw-cut-polygon-mode",
"severity": "critical",
"affectedVersions": [
"2.0.5"
]
},
{
"name": "@orbitgtbelgium/mapbox-gl-draw-scale-rotate-mode",
"severity": "critical",
"affectedVersions": [
"1.1.1"
]
},
{
"name": "@orbitgtbelgium/orbit-components",
"severity": "critical",
"affectedVersions": [
"1.2.9"
]
},
{
"name": "@orbitgtbelgium/time-slider",
"severity": "critical",
"affectedVersions": [
"1.0.187"
]
},
{
"name": "@osmanekrem/bmad",
"severity": "critical",
"affectedVersions": [
"1.0.6"
]
},
{
"name": "@osmanekrem/error-handler",
"severity": "critical",
"affectedVersions": [
"1.2.2"
]
},
{
"name": "@pergel/cli",
"severity": "critical",
"affectedVersions": [
"0.11.1"
]
},
{
"name": "@pergel/module-box",
"severity": "critical",
"affectedVersions": [
"0.6.1"
]
},
{
"name": "@pergel/module-graphql",
"severity": "critical",
"affectedVersions": [
"0.6.1"
]
},
{
"name": "@pergel/module-ui",
"severity": "critical",
"affectedVersions": [
"0.0.9"
]
},
{
"name": "@pergel/nuxt",
"severity": "critical",
"affectedVersions": [
"0.25.5"
]
},
{
"name": "@posthog/agent",
"severity": "critical",
"affectedVersions": [
"1.24.1"
]
},
{
"name": "@posthog/ai",
"severity": "critical",
"affectedVersions": [
"7.1.2"
]
},
{
"name": "@posthog/automatic-cohorts-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/bitbucket-release-tracker",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/cli",
"severity": "critical",
"affectedVersions": [
"0.5.15"
]
},
{
"name": "@posthog/clickhouse",
"severity": "critical",
"affectedVersions": [
"1.7.1"
]
},
{
"name": "@posthog/core",
"severity": "critical",
"affectedVersions": [
"1.5.6"
]
},
{
"name": "@posthog/currency-normalization-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/customerio-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/databricks-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/drop-events-on-property-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/event-sequence-timer-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/filter-out-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/first-time-event-tracker",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/geoip-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/github-release-tracking-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/gitub-star-sync-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/heartbeat-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/hedgehog-mode",
"severity": "critical",
"affectedVersions": [
"0.0.42"
]
},
{
"name": "@posthog/icons",
"severity": "critical",
"affectedVersions": [
"0.36.1"
]
},
{
"name": "@posthog/ingestion-alert-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/intercom-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/kinesis-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/laudspeaker-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/lemon-ui",
"severity": "critical",
"affectedVersions": [
"0.0.1"
]
},
{
"name": "@posthog/maxmind-plugin",
"severity": "critical",
"affectedVersions": [
"0.1.6"
]
},
{
"name": "@posthog/migrator3000-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/netdata-event-processing",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/nextjs",
"severity": "critical",
"affectedVersions": [
"0.0.3"
]
},
{
"name": "@posthog/nextjs-config",
"severity": "critical",
"affectedVersions": [
"1.5.1"
]
},
{
"name": "@posthog/nuxt",
"severity": "critical",
"affectedVersions": [
"1.2.9"
]
},
{
"name": "@posthog/pagerduty-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/piscina",
"severity": "critical",
"affectedVersions": [
"3.2.1"
]
},
{
"name": "@posthog/plugin-contrib",
"severity": "critical",
"affectedVersions": [
"0.0.6"
]
},
{
"name": "@posthog/plugin-server",
"severity": "critical",
"affectedVersions": [
"1.10.8"
]
},
{
"name": "@posthog/plugin-unduplicates",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/postgres-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/react-rrweb-player",
"severity": "critical",
"affectedVersions": [
"1.1.4"
]
},
{
"name": "@posthog/rrdom",
"severity": "critical",
"affectedVersions": [
"0.0.31"
]
},
{
"name": "@posthog/rrweb",
"severity": "critical",
"affectedVersions": [
"0.0.31"
]
},
{
"name": "@posthog/rrweb-player",
"severity": "critical",
"affectedVersions": [
"0.0.31"
]
},
{
"name": "@posthog/rrweb-record",
"severity": "critical",
"affectedVersions": [
"0.0.31"
]
},
{
"name": "@posthog/rrweb-replay",
"severity": "critical",
"affectedVersions": [
"0.0.19"
]
},
{
"name": "@posthog/rrweb-snapshot",
"severity": "critical",
"affectedVersions": [
"0.0.31"
]
},
{
"name": "@posthog/rrweb-utils",
"severity": "critical",
"affectedVersions": [
"0.0.31"
]
},
{
"name": "@posthog/sendgrid-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/siphash",
"severity": "critical",
"affectedVersions": [
"1.1.2"
]
},
{
"name": "@posthog/snowflake-export-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/taxonomy-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/twilio-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/twitter-followers-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/url-normalizer-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/variance-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@posthog/web-dev-server",
"severity": "critical",
"affectedVersions": [
"1.0.5"
]
},
{
"name": "@posthog/wizard",
"severity": "critical",
"affectedVersions": [
"1.18.1"
]
},
{
"name": "@posthog/zendesk-plugin",
"severity": "critical",
"affectedVersions": [
"0.0.8"
]
},
{
"name": "@postman/aether-icons",
"severity": "critical",
"affectedVersions": [
"2.23.2",
"2.23.3",
"2.23.4"
]
},
{
"name": "@postman/csv-parse",
"severity": "critical",
"affectedVersions": [
"4.0.3",
"4.0.4",
"4.0.5"
]
},
{
"name": "@postman/final-node-keytar",
"severity": "critical",
"affectedVersions": [
"7.9.1",
"7.9.2",
"7.9.3"
]
},
{
"name": "@postman/mcp-ui-client",
"severity": "critical",
"affectedVersions": [
"5.5.1",
"5.5.2",
"5.5.3"
]
},
{
"name": "@postman/node-keytar",
"severity": "critical",
"affectedVersions": [
"7.9.4",
"7.9.5",
"7.9.6"
]
},
{
"name": "@postman/pm-bin-linux-x64",
"severity": "critical",
"affectedVersions": [
"1.24.3",
"1.24.4",
"1.24.5"
]
},
{
"name": "@postman/pm-bin-macos-arm64",
"severity": "critical",
"affectedVersions": [
"1.24.3",
"1.24.4",
"1.24.5"
]
},
{
"name": "@postman/pm-bin-macos-x64",
"severity": "critical",
"affectedVersions": [
"1.24.3",
"1.24.4",
"1.24.5"
]
},
{
"name": "@postman/pm-bin-windows-x64",
"severity": "critical",
"affectedVersions": [
"1.24.3",
"1.24.4",
"1.24.5"
]
},
{
"name": "@postman/postman-collection-fork",
"severity": "critical",
"affectedVersions": [
"4.3.3",
"4.3.4",
"4.3.5"
]
},
{
"name": "@postman/postman-mcp-cli",
"severity": "critical",
"affectedVersions": [
"1.0.3",
"1.0.4",
"1.0.5"
]
},
{
"name": "@postman/postman-mcp-server",
"severity": "critical",
"affectedVersions": [
"2.4.10",
"2.4.11",
"2.4.12"
]
},
{
"name": "@postman/pretty-ms",
"severity": "critical",
"affectedVersions": [
"6.1.1",
"6.1.2",
"6.1.3"
]
},
{
"name": "@postman/secret-scanner-wasm",
"severity": "critical",
"affectedVersions": [
"2.1.2",
"2.1.3",
"2.1.4"
]
},
{
"name": "@postman/tunnel-agent",
"severity": "critical",
"affectedVersions": [
"0.6.5",
"0.6.6",
"0.6.7"
]
},
{
"name": "@postman/wdio-allure-reporter",
"severity": "critical",
"affectedVersions": [
"0.0.7",
"0.0.8",
"0.0.9"
]
},
{
"name": "@postman/wdio-junit-reporter",
"severity": "critical",
"affectedVersions": [
"0.0.4",
"0.0.5",
"0.0.6"
]
},
{
"name": "@pradhumngautam/common-app",
"severity": "critical",
"affectedVersions": [
"1.0.2"
]
},
{
"name": "@productdevbook/animejs-vue",
"severity": "critical",
"affectedVersi