MAL-2025-46974
MAL-2025-46974
L0 present onlymalwarecriticalMalicious code in debug (npm). 3 of 13 watched services resolved a compromised version; 3 did so while it was still installable; none is reachable from first-party code.
- lockfile resolved while installable
- L2 act now
- L1 imported
- L0 present only
- unscanned
Which of my services are exposed, and at what level?
0 act now
| service | verdict | lockfiles | pulled in via | latest commit | |
|---|---|---|---|---|---|
| ChrisTregaskis/ai-research-automation | L0 present only | 3 | eslint@8.57.1 · 0 hops | 6681e87 · 2025-09-09 15:54:36Z | open → |
| GoMake-ltd/n8n-node-gomake | L0 present only | 1 | eslint@8.57.1 · 0 hops | c361ccf · 2025-09-08 14:09:18Z | open → |
| LVQT-ss/cakestory-api | L0 present only | 2 | agent-base@6.0.2 · 0 hops | 5789d20 · 2025-09-13 04:37:42Z | open → |
notes ·verdict is per service, highest across its lockfiles. unscanned means the service resolves an affected version but its source was not read — not that it is clean.
Membership is exact (RESOLVED = the lockfile's flattened install tree). Explanation paths are the 3 shortest per lockfile, not all of them.
Which versions were installable, and for how long?
1 removed
| version | published (exact) | live until | state |
|---|---|---|---|
| debug@4.4.2first | 2025-09-08 13:12:39Z | 2025-09-08 14:26:51Zupper bound | removed |
notes ·live_to is an upper bound: npm publishes no takedown time; we use min(next surviving publish, advisory published).
Who pulled it in while it was still installable?
6 pin removed
| service | lockfile | resolved at | commit | in window | window |
|---|---|---|---|---|---|
| LVQT-ss/cakestory-api | debug@4.4.2 | 2025-09-08 14:05:12Z | 458e59e | yes · pins removed | 2025-09-08 13:12:39Z → 2025-09-08 14:26:51Z upper bound |
| GoMake-ltd/n8n-node-gomake | debug@4.4.2 | 2025-09-08 14:09:18Z | c361ccf | yes · pins removed | 2025-09-08 13:12:39Z → 2025-09-08 14:26:51Z upper bound |
| ChrisTregaskis/ai-research-automation | debug@4.4.2 | 2025-09-08 15:04:59Z | 80fc6d0 | no · pins removed | 2025-09-08 13:12:39Z → 2025-09-08 14:26:51Z upper bound |
| ChrisTregaskis/ai-research-automation | debug@4.4.2 | 2025-09-08 16:55:24Z | 5b74cd6 | no · pins removed | 2025-09-08 13:12:39Z → 2025-09-08 14:26:51Z upper bound |
| ChrisTregaskis/ai-research-automation | debug@4.4.2 | 2025-09-09 15:54:36Z | 6681e87 | no · pins removed | 2025-09-08 13:12:39Z → 2025-09-08 14:26:51Z upper bound |
| LVQT-ss/cakestory-api | debug@4.4.2 | 2025-09-13 04:37:42Z | 5789d20 | no · pins removed | 2025-09-08 13:12:39Z → 2025-09-08 14:26:51Z upper bound |
notes ·live_from is exact (npm keeps the publish timestamp after erasing the version). live_to is an upper bound where marked — npm publishes no takedown time.
in_window: the pin was committed while the artifact was installable; it does not prove an install happened. pinned_removed: the lockfile pins a version npm has erased, which is only possible while it was live — commit time is irrelevant.
What else could the same maintainers reach?
32 packages
| package | weekly downloads | services that would be reached |
|---|---|---|
| color-convert | 287,659,317 | 13ai-research-automation, n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| util-deprecate | 123,634,143 | 12n8n-node-gomake, insomnia, cakestory-api, documenso, koa, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| agent-base | 218,048,895 | 10insomnia, cakestory-api, documenso, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| https-proxy-agent | 164,323,294 | 10insomnia, cakestory-api, documenso, uptime-kuma, Aider-Chat, medplum, socket.io, bootstrap, bruno, wagtail |
| is-arrayish | 103,734,318 | 10insomnia, cakestory-api, documenso, koa, uptime-kuma, medplum, socket.io, bootstrap, bruno, wagtail |
| http-proxy-agent | 116,242,737 | 9insomnia, cakestory-api, documenso, uptime-kuma, Aider-Chat, medplum, socket.io, bruno, wagtail |
| error-ex | 79,832,971 | 9insomnia, documenso, koa, uptime-kuma, medplum, socket.io, bootstrap, bruno, wagtail |
| data-uri-to-buffer | 79,532,327 | 5insomnia, documenso, uptime-kuma, medplum, socket.io |
| color-string | 43,984,374 | — not computed |
| socks-proxy-agent | 38,234,480 | — not computed |
| color | 34,051,424 | — not computed |
| simple-swizzle | 25,876,284 | — not computed |
| proxy-agent | 24,531,177 | — not computed |
| get-uri | 23,982,124 | — not computed |
| pac-proxy-agent | 23,844,963 | — not computed |
limits ·past the computed cap the reach cell reads “— not computed” — never a 0.
32 co-maintained packages; exposure computed for the 8 most downloaded.
twofa / account_created are not exposed by the public npm registry; shown as unknown, never guessed.
'services at risk' = services resolving the co-maintained package today — the exposure IF that package is compromised next, not exposure to this incident.
Which look-alike names exist?
1 kind
notes ·The corpus is packages present in the ingested graph, so near-neighbours may be legitimate look-alikes; distance and kind are facts, 'typosquat' is a hypothesis.
What is the blast radius, service by service?
0 unscanned
notes ·3 services · 6 lockfile snapshots · 32 co-maintained packages · composed in 16.45 s