Language:
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
https://github.com/advisories/GHSA-frh7-2f84-v9mw
https://github.com/advisories/GHSA-6jp5-hh4c-8c5h
https://github.com/advisories/GHSA-pxx3-g568-hxr4
https://github.com/advisories/GHSA-5fvm-p68v-5wmh
https://github.com/advisories/GHSA-4x49-vf9v-38px
https://github.com/advisories/GHSA-qrmh-qg46-72pp
https://github.com/advisories/GHSA-286p-vc9p-p5qv
Severity: High
ID: 265444
File Name: npm_supply_chain_attack_08-09-2025.nasl
Version: 1.1
Type: local
Family: Misc.
Published: 9/19/2025
Updated: 9/19/2025
Configuration: Enable thorough checks (optional)
Supported Sensors: Nessus
Risk Factor: Low
Score: 3.2
Risk Factor: High
Base Score: 8.8
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score Source: CVE-2025-59330
CPE: cpe:/a:nodejs:node.js
Required KB Items: Host/nodejs/modules/enumerated
Patch Publication Date: 9/8/2025
Vulnerability Publication Date: 9/8/2025
CVE: CVE-2025-59140, CVE-2025-59141, CVE-2025-59142, CVE-2025-59143, CVE-2025-59144, CVE-2025-59145, CVE-2025-59162, CVE-2025-59330, CVE-2025-59331