The "Shai-Hulud" NPM Supply Chain Attack involves a self-replicating worm which targets Node Package Manager (NPM) package containers across the open-source JavaScript ecosystem with the intention of collecting sensitive authentication credentials. The impacted packages are commonly used as developer assets in the development of other software products, which can lead to vulnerabilities within those products.
To ensure customer security, One Identity followed industry best practices and tested the products listed below. Our testing did not identify any impacted packages in these products. No action is required from our customers at this time.
NOTE: We will continue to monitor this evolving situation and enhance our toolset if deemed necessary.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. 이용 약관 개인정보 보호정책 Cookie Preference Center