NPM stylus package contained malicious code and was removed from the registry
1–10 of 45 posts
Re: NPM stylus package contained malicious code and was removed from the registry
#2Re: NPM stylus package contained malicious code and was removed from the registry
#3Maintainer @iChenLei reports they are negotiating with npm officials to restore access: https://github.com/stylus/stylus/issues/2938
Re: NPM stylus package contained malicious code and was removed from the registry
#4https://github.com/advisories/GHSA-fh4q-jc76-r59p
I'm still unsure if it's a mistake on NPM side or if stylus and the authors are compromised
Re: NPM stylus package contained malicious code and was removed from the registry
#5Re: NPM stylus package contained malicious code and was removed from the registry
#6This advisory is pointing to the stylus package https://github.com/advisories/GHSA-fh4q-jc76-r59p I'm still unsure if it's a mistake on NPM side or if stylus and the authors are compromised
Many suggestions for workarounds, but if the GHSA is indeed accurate (all versions affected) then that seems unwise.
Re: NPM stylus package contained malicious code and was removed from the registry
#7This advisory is pointing to the stylus package https://github.com/advisories/GHSA-fh4q-jc76-r59p I'm still unsure if it's a mistake on NPM side or if stylus and the authors are compromised
It's so hard to triage this when no justification has been provided for the advisory. Was the GHSA released in response to npm pulling the package, or vice versa? Many suggestions for workarounds, but if the GHSA is indeed accurate (all versions affected) then that seems unwise.
Re: NPM stylus package contained malicious code and was removed from the registry
#8Removing the entire package is pretty unusual, normally it's only specific compromised versions.
Re: NPM stylus package contained malicious code and was removed from the registry
#9Earlier quoted context omitted.
It's so hard to triage this when no justification has been provided for the advisory. Was the GHSA released in response to npm pulling the package, or vice versa? Many suggestions for workarounds, but if the GHSA is indeed accurate (all versions affected) then that seems unwise.
Also if all the versions are affected this malware is in stylus since 2010. Honestly, it sounds improbable to me that a malware exists unnoticed in open source software for 15 years. However, even if improbable it's better to play safe and just override the installation of stylus ( especially if you are not using it ) with an empty package until more information is released
Re: NPM stylus package contained malicious code and was removed from the registry
#10This advisory is pointing to the stylus package https://github.com/advisories/GHSA-fh4q-jc76-r59p I'm still unsure if it's a mistake on NPM side or if stylus and the authors are compromised
It's so hard to triage this when no justification has been provided for the advisory. Was the GHSA released in response to npm pulling the package, or vice versa? Many suggestions for workarounds, but if the GHSA is indeed accurate (all versions affected) then that seems unwise.
And the GHSA advisory: 2025-07-23T03:03:56Z
So the GHSA was released after the pull (by a minute).