# Supply-chain malware check on Node-RED

**URL:** <https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988>\
**Category:** General\
**Tags:** security\
**Created:** [8 September 2025 17:24 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988 "2025-09-08T17:24:45Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![augjoh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/augjoh/32/26464_2.png) [@augjoh](https://discourse.nodered.org/u/augjoh)\
**Post date:** [8 September 2025 17:24 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/1 "2025-09-08T17:24:45Z")

</div>

There is a compromised dependency drawn into Node-RED. ( [Malware in debug · GHSA-8mgj-vmr8-frr6 · GitHub Advisory Database · GitHub](https://github.com/advisories/GHSA-8mgj-vmr8-frr6) )

How can I avoid installing this dependency?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [8 September 2025 18:20 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/2 "2025-09-08T18:20:07Z")

</div>

You need to check what version. I've just done a check on my up-to-date installation and got this:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/1/418e968bec1242525abe38c38bc0de5182f84c96.png)

As you can see, there are various versions of debug but none newer than 4.4.1.

4.4.2 is the corrupted version.

@knolleary, @Steve-Mcl, @dceejay, @joepavitt - tagging you guys because it isn't only debug, quite a number of high-profile npm packages have been compromised in a new supply-chain hack.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [8 September 2025 18:24 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/3 "2025-09-08T18:24:11Z")

</div>

4.4.2 should get pulled soon I would think (hope)  
as above - the version I have in my projects (node red or otherwise) is 4.4.1

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [8 September 2025 18:25 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/4 "2025-09-08T18:25:08Z")

</div>

It is pulled already.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [8 September 2025 18:38 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/5 "2025-09-08T18:38:27Z")

</div>

Can I check, is the main node-red repo protected with dependabot and snyk?

I've also added a requirement for signed git commits to uibuilder as well as those 2 + a couple of other security/code quality checks.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [8 September 2025 18:41 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/6 "2025-09-08T18:41:33Z")

</div>

> [@TotallyInformation](#):
>
> dependabot

[https://github.com/node-red/node-red/security/dependabot](https://github.com/node-red/node-red/security/dependabot)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [8 September 2025 18:55 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/7 "2025-09-08T18:55:17Z")

</div>

It is worth getting snyk on the case as well.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [8 September 2025 18:57 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/8 "2025-09-08T18:57:33Z")

</div>

Hi @augjoh, hope you don't mind but I've re-titled the post because it is clear that Node-RED has not been compromised with this supply-chain mega-hack.

I can also confirm that none of my active nodes including uibuilder and moment are impacted, neither is my web-components library.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [8 September 2025 19:11 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/9 "2025-09-08T19:11:06Z")

</div>

Here you go peeps.

The infected versions - to check if you have any of them.

```auto
npm ls "backslash@0.2.1" "chalk-template@1.1.1" "supports-hyperlinks@4.1.1" "has-ansi@6.0.1" "simple-swizzle@0.2.3" "color-string@2.1.1" "error-ex@1.3.3" "color-name@2.0.1" "is-arrayish@0.3.3" "slice-ansi@7.1.1" "color-convert@3.1.1" "wrap-ansi@9.0.1" "ansi-regex@6.2.1" "supports-color@10.2.1" "strip-ansi@7.1.1" "chalk@5.6.1" "debug@4.4.2" "ansi-styles@6.2.2"

```

and just to test (I tested for a none infected version)

```auto
marcusdavies@Marcuss-Mini untitled folder % npm ls "backslash@0.2.1" "chalk-template@1.1.1" "supports-hyperlinks@4.1.1" "has-ansi@6.0.1" "simple-swizzle@0.2.3" "color-string@2.1.1" "error-ex@1.3.3" "color-name@2.0.1" "is-arrayish@0.3.3" "slice-ansi@7.1.1" "color-convert@3.1.1" "wrap-ansi@9.0.1" "ansi-regex@6.2.1" "supports-color@10.2.1" "strip-ansi@7.1.1" "chalk@5.6.1" "debug@4.4.1" "ansi-styles@6.2.2"
untitled folder@ /Users/marcusdavies/Desktop/untitled folder
├─┬ node-red-contrib-zwave-js@10.0.0 extraneous
│ ├─┬ @alcalzone/jsonl-db@3.1.1 extraneous
│ │ └─┬ alcalzone-shared@4.0.8 extraneous
│ │ └── debug@4.4.1 deduped
│ ├─┬ @eslint/config-array@0.21.0 extraneous
│ │ └── debug@4.4.1 deduped
│ ├─┬ @eslint/eslintrc@3.3.1 extraneous
│ │ └── debug@4.4.1 deduped
│ ├─┬ @homebridge/ciao@1.3.4 extraneous
│ │ └── debug@4.4.1 deduped
│ ├─┬ @iconify/utils@2.3.0 extraneous
│ │ └── debug@4.4.1 deduped
│ ├─┬ @serialport/binding-mock@10.2.2 extraneous
│ │ └── debug@4.4.1 deduped
│ ├── debug@4.4.1 extraneous
│ └─┬ eslint@9.34.0 extraneous
│ └── debug@4.4.1 deduped
└─┬ node-red@4.1.0
  ├─┬ @node-red/editor-api@4.1.0
  │ └─┬ memorystore@1.6.7
  │ └── debug@4.4.1
  └─┬ @node-red/nodes@4.1.0
    ├─┬ https-proxy-agent@5.0.1
    │ ├─┬ agent-base@6.0.2
    │ │ └── debug@4.4.1
    │ └── debug@4.4.1
    └─┬ mqtt@5.11.0
      ├── debug@4.4.1
      ├─┬ mqtt-packet@9.0.2
      │ └── debug@4.4.1
      └─┬ number-allocator@1.0.14
        └── debug@4.4.1

marcusdavies@Marcuss-Mini untitled folder % 

```

---

<div class="post-metadata">

**Author:** ![AllanOricil](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/allanoricil/32/106911_2.png) [@AllanOricil](https://discourse.nodered.org/u/AllanOricil)\
**Post date:** [8 September 2025 19:26 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/10 "2025-09-08T19:26:51Z")

</div>

What happens to node-red versions that have dependencies that have vulnerabilities? Are they marked as deprecated or removed from npm?

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [9 September 2025 09:02 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/11 "2025-09-09T09:02:09Z")

</div>

> [@AllanOricil](#):
>
> node-red versions that have dependencies that have vulnerabilities? Are they marked as deprecated or removed from npm?

I don't believe that dependabot checks old releases to be honest. So I doubt they would be picked up. I think that you can submit multiple branches to Snyk for testing but again, not sure it keeps testing if you haven't pushed any updates to the branch.

> [@marcus-j-davies](#):
>
> Here you go peeps.
> 
> The infected versions - to check if you have any of them.

Nice, don't forget to also check `-g` for global packages. UIBUILDER has its own packages you can install too so you may need to separately check the uibRoot, especially if you've moved it from its default location.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [8 December 2025 09:02 UTC](https://discourse.nodered.org/t/supply-chain-malware-check-on-node-red/98988/12 "2025-12-08T09:02:46Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
