MAL-2025-46969
MAL-2025-46969
L0 present onlymalwarecriticalMalicious code in chalk (npm). 1 of 13 watched services resolved a compromised version; 1 did so while it was still installable; none is reachable from first-party code.
- lockfile resolved while installable
- L2 act now
- L1 imported
- L0 present only
- unscanned
Which of my services are exposed, and at what level?
0 act now
| service | verdict | lockfiles | pulled in via | latest commit | |
|---|---|---|---|---|---|
| lperry65/Aider-Chat | L0 present only | 1 | lint-staged@16.1.6 · 0 hops | b1d64b4 · 2025-09-08 17:18:24Z | open → |
notes ·verdict is per service, highest across its lockfiles. unscanned means the service resolves an affected version but its source was not read — not that it is clean.
Membership is exact (RESOLVED = the lockfile's flattened install tree). Explanation paths are the 3 shortest per lockfile, not all of them.
Which versions were installable, and for how long?
1 removed
| version | published (exact) | live until | state |
|---|---|---|---|
| chalk@5.6.1first | 2025-09-08 13:13:05Z | 2025-09-08 14:47:54Zupper bound | removed |
notes ·live_to is an upper bound: npm publishes no takedown time; we use min(next surviving publish, advisory published).
Who pulled it in while it was still installable?
1 pin removed
| service | lockfile | resolved at | commit | in window | window |
|---|---|---|---|---|---|
| lperry65/Aider-Chat | chalk@5.6.1 | 2025-09-08 17:18:24Z | b1d64b4 | no · pins removed | 2025-09-08 13:13:05Z → 2025-09-08 14:47:54Z upper bound |
notes ·live_from is exact (npm keeps the publish timestamp after erasing the version). live_to is an upper bound where marked — npm publishes no takedown time.
in_window: the pin was committed while the artifact was installable; it does not prove an install happened. pinned_removed: the lockfile pins a version npm has erased, which is only possible while it was live — commit time is irrelevant.
What else could the same maintainers reach?
283 packages
| package | weekly downloads | services that would be reached |
|---|---|---|
| ansi-styles | 571,691,924 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| strip-ansi | 432,082,533 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| string-width | 415,333,702 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| ansi-regex | 403,212,379 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| wrap-ansi | 360,294,876 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| supports-color | 332,865,084 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| type-fest | 315,194,335 | 12ai-research-automation, n8n-node-gomake, insomnia, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| escape-string-regexp | 298,664,858 | 12ai-research-automation, n8n-node-gomake, insomnia, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| p-limit | 275,763,785 | — not computed |
| find-up | 271,310,344 | — not computed |
| has-flag | 268,889,263 | — not computed |
| locate-path | 264,631,832 | — not computed |
| p-locate | 263,528,764 | — not computed |
| path-key | 229,214,082 | — not computed |
| is-fullwidth-code-point | 218,280,345 | — not computed |
limits ·past the computed cap the reach cell reads “— not computed” — never a 0.
283 co-maintained packages; exposure computed for the 8 most downloaded.
twofa / account_created are not exposed by the public npm registry; shown as unknown, never guessed.
'services at risk' = services resolving the co-maintained package today — the exposure IF that package is compromised next, not exposure to this incident.
Which look-alike names exist?
0 kinds

no near-names in the ingested corpus for chalk
notes ·The corpus is packages present in the ingested graph, so near-neighbours may be legitimate look-alikes; distance and kind are facts, 'typosquat' is a hypothesis.
What is the blast radius, service by service?
0 unscanned
notes ·1 service · 1 lockfile snapshot · 283 co-maintained packages · composed in 30.99 s