Threat Briefing

ChainDrop: The npm Worm That Poisoned 444 Packages in Under Four Hours

Supply Chain Threat Briefing5 August 2026Executive Summary

On the morning of 4 August 2026, a single compromised developer account set off the fastest self-spreading software supply chain incident the open source ecosystem has seen. Within four hours, malicious code had inserted itself into 444 software packages across 2,212 published versions, jumping automatically from one company's build system to the next by stealing credentials along the way. This briefing explains what happened in plain terms, who is exposed, and the small number of decisions leadership needs to make this week.

ChainDrop
444 Packages · 2,212 Versions · 4 Hours
444
Packages poisoned
2,212
Malicious versions
450M+
Weekly downloads in scope
14+
Organisations hit

Observed between 09:40 and 13:20 UTC on 4 August 2026. The campaign was still being cleaned up at the time of writing.

The Short Version for Leadership

An attacker took control of the GitHub account of a widely trusted open source maintainer. Rather than stealing a publishing key, they edited the source code of three of his projects and let the projects' own automated release systems do the publishing for them. The result: malicious software releases that were signed, attested and, by every automated integrity check available today, indistinguishable from legitimate ones.

The code that shipped was not a simple data stealer. It was a worm. Once it landed inside a company's build pipeline, it collected that company's own credentials and used them to publish itself into that company's packages — which then reached that company's customers. No further attacker involvement was needed at any step.

The uncomfortable headline: the industry's current gold standard for trusting a software release — verified provenance and trusted publishing — did not stop this. Provenance proves which source code was built. It cannot prove that the source code change was authorised.

Why This One Matters More Than the Usual Package Incident

  • Speed. From first poisoned release to 444 affected packages took under four hours. Human-paced incident response cannot keep up with credential-driven automation.
  • Reach. The first three packages alone sit beneath roughly 450 million weekly downloads and are indirect dependencies of a very large share of the JavaScript ecosystem, including common linting and caching tooling. Most exposed organisations never chose these packages; they arrived several layers deep.
  • Direction of travel. Within two hours the worm had moved out of public developer tooling and into corporate design systems and SDKs belonging to named enterprises — meaning private, commercial software supply chains were affected, not just hobby projects.
  • Trust erosion. Because every malicious release carried a valid attestation, organisations that had invested in provenance verification received no warning at all.

How the Attack Worked

  1. Account takeover. The attacker gained control of a maintainer's GitHub account and pushed changes directly to the main branch, bypassing review.
  2. Legitimate machinery, malicious input. They tagged a release. The project's ordinary, untouched release automation built and published it — complete with a genuine signature.
  3. Automatic execution on install. The package was configured to run a small script the moment anyone installed it. Nobody had to open or run the software.
  4. A second stage arrives. That script downloaded a legitimate, widely used developer runtime directly from an official source, so the network activity looked entirely normal, then used it to run the real payload.
  5. Credential harvesting. The payload swept the machine and the build environment for publishing tokens, cloud credentials, container platform access and secret store access.
  6. Self-propagation. With those stolen credentials, it republished itself into the victim organisation's own packages — and the cycle restarted inside the next company.
  7. Hidden command and control. Instead of a fixed attacker server that could be blocked or seized, the malware looked up its current destination from a public blockchain record. There is no single address to take down.

It also left itself behind. On developer laptops it planted start-up hooks in editor and AI-assistant configuration folders, so it would run again the next time a developer simply opened a project, and installed a watcher designed to trigger further activity at the moment the stolen access token is revoked.

Who Was Affected

Organisation or namespacePackagesTier
jaredwray ecosystem (keyv, flat-cache, file-entry-cache, cacheable, cacheable-request, cache-manager, ecto and four @cacheable/* packages)11Full worm carriers
@servicetitan141Worm propagated
@onereach78Worm propagated
@or-sdk74Worm propagated
@ornikar42Worm propagated
@qlik28Worm propagated
@nebula.js22Worm propagated
@umacloud8Worm propagated
@arv-bedrock5Worm propagated
@deliveroo, @picsart, @adminide-stack2 eachWorm propagated
@hubsync, @thiennq, @workbench-stack1 eachWorm propagated
Unscoped second-wave packages (picasso.js, qlik-chart-modules, folder-lint, verdaccio-okta-oauth and 22 others)26Worm propagated

Eight publisher accounts are known to have been used to push malicious releases during the campaign: jaredwray, thiennq, hubsyncdevops, abarreir-ornikar, sitthidet_arv, rooci, picsart-npm-service-owner and onereach.user.

The Eleven Original Carrier Packages

These are the first-tier compromises: packages that shipped the complete worm, published through the projects' own trusted release pipelines. If any of these versions appear anywhere in your dependency records, treat the environment as compromised.

PackageMalicious versionPublished (UTC)Weekly downloads
keyv6.0.009:35:00153,717,238
flat-cache6.1.2410:10:55149,868,983
file-entry-cache11.1.610:13:02147,558,494
cacheable-request13.0.2010:11:2433,963,726
@cacheable/utils2.5.110:14:218,713,375
cacheable2.5.110:10:447,877,004
@cacheable/memory2.2.110:11:297,176,667
cache-manager7.2.1010:14:414,281,731
@cacheable/node-cache3.1.210:10:341,555,151
ecto5.0.110:28:011,293
@cacheable/net2.1.110:09:44975

Complete List of Affected Packages

All 444 packages and 2,212 versions identified during the observation window are listed below, including the eleven carriers and the 433 packages republished automatically by the worm. Many packages had long histories of older versions republished with the payload attached, which is why the version count is so much higher than the package count. Use the search box to check a specific name against your inventory, and audit transitive dependencies as well as direct ones.

PackageCompromised versions
@adminide-stack/clock-tik-browser12.0.24
@adminide-stack/yantra-mobile12.0.33
@arv-bedrock/auth1.1.7, 1.1.8
@arv-bedrock/auth-admin1.0.2, 1.0.3
@arv-bedrock/auth-sso1.6.1, 1.6.2
@arv-bedrock/auth-sso-backend1.7.1, 1.7.2
@arv-bedrock/logger1.7.1, 1.7.2
babel-plugin-linaria-css-to-undefined0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.3.5, 0.3.6, 0.3.7, 0.3.8, 0.3.9, 0.3.10, 0.3.11, 0.3.12, 0.3.13, 0.3.14, 0.3.15, 0.3.16, 0.3.17
cache-manager7.2.10
cacheable2.5.1
cacheable-request13.0.20
@cacheable/memory2.2.1
@cacheable/net2.1.1
@cacheable/node-cache3.1.2
@cacheable/utils2.5.1
conv-context-next1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10
@deliveroo/determinator0.2.1
@deliveroo/reevent1.0.1
ecto5.0.1
editable-contracts0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16, 0.0.17, 0.0.18, 0.0.19, 0.0.20, 0.0.21, 0.0.22, 0.0.23, 0.0.24, 0.0.25, 0.0.26, 0.0.27
eslint-plugin-folder-schema1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21
example-js-project1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.8, 1.0.9, 1.0.10, 1.0.11
file-entry-cache11.1.6
flat-cache6.1.24
folder-lint1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21
frontend-orb4.4.1, 4.4.2, 4.4.3, 4.4.4, 4.4.5, 4.4.6, 4.4.7, 4.4.8, 4.4.9, 4.4.10, 4.4.11, 4.4.12, 4.4.13, 4.4.14, 4.4.15, 4.4.16, 4.4.17, 4.4.18
hamus.js0.4.1
http-metrics-middleware2.2.2
@hubsync/web-sdk-react6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.3.15, 6.3.16, 6.3.17, 6.3.18, 6.3.19, 6.3.20, 6.3.21, 6.3.22, 6.3.23, 6.3.24, 6.3.25, 6.3.26, 6.3.27, 6.3.28, 6.3.29, 6.3.30, 6.3.31, 6.3.32, 6.3.33
keyv6.0.0
native-frontend-orb1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9, 1.1.10, 1.1.11, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19
@nebula.js/cli7.1.2
@nebula.js/cli-build7.1.2
@nebula.js/cli-sense7.1.2
@nebula.js/cli-serve7.1.2
@nebula.js/locale0.6.2
@nebula.js/nucleus0.5.1
@nebula.js/sn-action-button2.3.1
@nebula.js/sn-animator2.13.1
@nebula.js/sn-distributionplot1.0.7
@nebula.js/sn-layout-container4.4.1
@nebula.js/sn-line-chart2.7.1
@nebula.js/sn-listbox0.19.3
@nebula.js/sn-map0.12.7
@nebula.js/sn-nav-menu0.14.2
@nebula.js/sn-org-chart1.7.1
@nebula.js/sn-shape1.5.1
@nebula.js/sn-slider0.20.1
@nebula.js/sn-tabbed-container2.4.1
@nebula.js/snapshooter0.6.1
@nebula.js/stardust7.1.2
@nebula.js/test-utils0.6.1
@nebula.js/theme0.6.1
@onereach/authorizer-helper0.0.11, 0.0.12, 0.0.13
@onereach/bandwidth-steps-voice-bxml0.1.1, 0.1.2, 0.1.3
@onereach/billing-dto27.2.1, 27.2.3
@onereach/billing-shared27.2.1, 27.2.2, 27.2.3
@onereach/cb-schema-translator1.3.1, 1.3.2, 1.3.3
@onereach/channel-transformer0.0.66, 0.0.67, 0.0.68
@onereach/channel-transformers0.0.5, 0.0.6, 0.0.7
@onereach/ckeditor5-build-classic30.0.1, 30.0.2, 30.0.3
@onereach/condition-builder1.0.8, 1.0.9, 1.0.10
@onereach/content-builder0.0.18, 0.0.19, 0.0.20
@onereach/content-builder-template-compiler0.0.3, 0.0.4, 0.0.5
@onereach/expression-components9.1.1, 9.1.2, 9.1.3
@onereach/font-icons27.0.2, 27.0.3, 27.0.4
@onereach/get-version-data3.1.2, 3.1.3, 3.1.4
@onereach/idw-apps0.1.3, 0.1.4, 0.1.5
@onereach/idw-contracts0.1.2, 0.1.3, 0.1.4
@onereach/idw-init-account-resources1.0.1, 1.0.2, 1.0.3
@onereach/idw-sdk0.1.2, 0.1.3, 0.1.4
@onereach/idw-ui-components0.1.2, 0.1.4
@onereach/lambda-invocation1.2.1, 1.2.2, 1.2.3
@onereach/messengers-infobip-sdk0.1.1, 0.1.2, 0.1.3
@onereach/or-browser0.0.48, 0.0.49, 0.0.50
@onereach/or-browser-next0.0.11, 0.0.12, 0.0.13
@onereach/or-content-builder-renderer0.0.2, 0.0.3, 0.0.4
@onereach/or-file-uploader-next0.0.8, 0.0.9, 0.0.10
@onereach/or-pro1.13.1, 1.13.2, 1.13.3
@onereach/or-sdk-agent-cli0.0.7, 0.0.8
@onereach/orest-cli2.4.1, 2.4.2, 2.4.3
@onereach/orest-input-cli1.18.1, 1.18.2, 1.18.3
@onereach/orest-jest-presets0.0.3, 0.0.4, 0.0.5
@onereach/orest-vue-demi-vue20.0.4, 0.0.5, 0.0.6
@onereach/orest-vue-demi-vue30.0.4, 0.0.5, 0.0.6
@onereach/orest-vue30.0.4, 0.0.5, 0.0.6
@onereach/phonenumber-interpreter0.0.18, 0.0.19, 0.0.20
@onereach/pnpm-audit-junit1.0.3, 1.0.5
@onereach/postcss-scoped-selector1.2.1, 1.2.2, 1.2.3
@onereach/regex-helper0.5.16, 0.5.17, 0.5.18
@onereach/regular-expressions0.5.23, 0.5.24, 0.5.25
@onereach/regular-expressions-test0.0.4, 0.0.5, 0.0.6
@onereach/rwc-client6.4.7, 6.4.8, 6.4.9
@onereach/salesforce-miaw-client0.0.3, 0.0.4, 0.0.5
@onereach/si-a-button0.0.3, 0.0.4, 0.0.5
@onereach/si-alert0.4.11, 0.4.12, 0.4.13
@onereach/si-checkbox0.6.5, 0.6.6, 0.6.7
@onereach/si-checkbox-group0.3.5, 0.3.6, 0.3.7
@onereach/si-code0.6.4, 0.6.5, 0.6.6
@onereach/si-collapsible-group0.6.4, 0.6.5, 0.6.6
@onereach/si-copyable-text0.4.11, 0.4.12, 0.4.13
@onereach/si-datepicker0.4.5, 0.4.6, 0.4.7
@onereach/si-divider0.4.11, 0.4.13
@onereach/si-dropdown-advanced0.4.5, 0.4.6, 0.4.7
@onereach/si-dropdown-simple0.4.5, 0.4.6, 0.4.7
@onereach/si-header0.4.11, 0.4.12, 0.4.13, 0.4.14
@onereach/si-list0.7.4, 0.7.6
@onereach/si-merge-tag-input0.4.5, 0.4.7
@onereach/si-radio-group0.3.5, 0.3.6, 0.3.7
@onereach/si-root0.9.4, 0.9.5, 0.9.6
@onereach/si-select0.1.3, 0.1.4, 0.1.5
@onereach/si-step-chooser0.4.4, 0.4.5, 0.4.6
@onereach/si-switch0.4.5, 0.4.6, 0.4.7
@onereach/si-text-message0.4.5, 0.4.6, 0.4.7
@onereach/si-textinput0.5.5, 0.5.6, 0.5.7
@onereach/si-validated-timestring-input0.3.5, 0.3.6, 0.3.7
@onereach/slack-helpers1.0.3, 1.0.4, 1.0.5
@onereach/ssml-editor2.0.12, 2.0.13, 2.0.14
@onereach/step-components0.1.37, 0.1.39
@onereach/step-conversation1.0.41, 1.0.42, 1.0.43
@onereach/step-run-snowflake-query0.1.1, 0.1.2, 0.1.3
@onereach/step-voice7.0.32, 7.0.33, 7.0.34
@onereach/styles27.0.2, 27.0.4
@onereach/time-interpreter1.0.30, 1.0.31, 1.0.32
@onereach/ts-memoize1.0.2, 1.0.3, 1.0.4
@onereach/types-contacts-api9.0.8, 9.0.9, 9.0.10
@onereach/ui-components27.0.2, 27.0.3, 27.0.4
@onereach/ui-components-common27.0.2, 27.0.3, 27.0.4
@onereach/ui-components-vue227.0.2, 27.0.3, 27.0.4
@onereach/v-event-calendar0.1.22, 0.1.23, 0.1.24
@onereach/webform0.3.13, 0.3.14, 0.3.15
@or-sdk/account-settings1.3.6, 1.3.7, 1.3.8
@or-sdk/accounts2.3.5, 2.3.7
@or-sdk/adapters0.3.6, 0.3.7, 0.3.8
@or-sdk/agents4.21.3, 4.21.4, 4.21.5
@or-sdk/api-tokens1.4.2, 1.4.3, 1.4.4
@or-sdk/api-tokens-lambda1.4.2, 1.4.4
@or-sdk/apps1.2.6, 1.2.7, 1.2.8
@or-sdk/auth0.38.1, 0.38.2, 0.38.3
@or-sdk/authorizer0.26.7, 0.26.8, 0.26.9
@or-sdk/base0.44.4, 0.44.5, 0.44.6
@or-sdk/billing27.2.1, 27.2.2, 27.2.3
@or-sdk/billing-internal27.2.1, 27.2.2, 27.2.3
@or-sdk/bot-templates2.2.5, 2.2.6, 2.2.7
@or-sdk/bots1.7.1, 1.7.2, 1.7.3
@or-sdk/card-templates2.2.5, 2.2.6, 2.2.7
@or-sdk/cards1.2.5, 1.2.6, 1.2.7
@or-sdk/ccp10.15.4, 10.15.5, 10.15.6
@or-sdk/chat0.3.1, 0.3.3
@or-sdk/contacts4.7.5, 4.7.6, 4.7.7
@or-sdk/content-request0.2.6, 0.2.7, 0.2.8
@or-sdk/data-hub0.26.5, 0.26.6, 0.26.7
@or-sdk/data-hub-svc2.3.5, 2.3.6, 2.3.7
@or-sdk/deployer1.7.5, 1.7.6, 1.7.7
@or-sdk/deployments2.1.5, 2.1.6, 2.1.7
@or-sdk/discovery1.12.1, 1.12.2, 1.12.3
@or-sdk/druid1.4.7, 1.4.8, 1.4.9
@or-sdk/event-manager1.1.5, 1.1.6, 1.1.7
@or-sdk/files3.11.6, 3.11.7, 3.11.8
@or-sdk/files-sync-node0.1.8, 0.1.9, 0.1.10
@or-sdk/flow-templates2.1.5, 2.1.6, 2.1.7
@or-sdk/flows2.7.8, 2.7.9, 2.7.10
@or-sdk/graph1.10.5, 1.10.6, 1.10.7
@or-sdk/hitl0.41.1, 0.41.2, 0.41.3
@or-sdk/identifiers0.27.6, 0.27.7, 0.27.8
@or-sdk/idw9.0.4, 9.0.5, 9.0.6
@or-sdk/idw-public1.6.6, 1.6.7, 1.6.8
@or-sdk/idw-skill1.4.1, 1.4.2, 1.4.3
@or-sdk/invitations1.4.8, 1.4.9, 1.4.10
@or-sdk/key-value-storage0.28.6, 0.28.7, 0.28.8
@or-sdk/keys1.2.6, 1.2.7, 1.2.8
@or-sdk/knowledge-models0.25.5, 0.25.6, 0.25.7
@or-sdk/library0.5.6, 0.5.7, 0.5.8
@or-sdk/library-categories0.2.6, 0.2.8
@or-sdk/library-source0.4.5, 0.4.6, 0.4.7
@or-sdk/library-types-v19.0.1, 9.0.2, 9.0.3
@or-sdk/library-types-v29.0.1, 9.0.2, 9.0.3
@or-sdk/lookup1.25.1, 1.25.2, 1.25.3
@or-sdk/markdowner0.5.1, 0.5.2, 0.5.3
@or-sdk/mcp-tools0.5.2, 0.5.3, 0.5.4
@or-sdk/notifications1.7.5, 1.7.6, 1.7.7
@or-sdk/password1.3.6, 1.3.7, 1.3.8
@or-sdk/payments3.2.5, 3.2.6, 3.2.7
@or-sdk/permissions2.8.1, 2.8.3
@or-sdk/permissions-cli1.4.1, 1.4.2, 1.4.3
@or-sdk/permissions-lambda2.5.1, 2.5.2, 2.5.3
@or-sdk/pgsql1.5.1, 1.5.2, 1.5.3
@or-sdk/providers0.3.6, 0.3.8
@or-sdk/qna3.4.2, 3.4.3, 3.4.4
@or-sdk/queue-manager1.4.6, 1.4.7, 1.4.8
@or-sdk/sdk-api0.29.2, 0.29.3, 0.29.4
@or-sdk/settings0.25.6, 0.25.7, 0.25.8
@or-sdk/sku-builder2.5.1, 2.5.2, 2.5.3
@or-sdk/source2.1.5, 2.1.6, 2.1.7
@or-sdk/source-api1.1.1, 1.1.2, 1.1.3
@or-sdk/step-templates2.2.6, 2.2.7
@or-sdk/store2.1.5, 2.1.6, 2.1.7
@or-sdk/tables0.28.5, 0.28.6, 0.28.7
@or-sdk/tags1.1.5, 1.1.6, 1.1.7
@or-sdk/tickets1.9.5, 1.9.6, 1.9.7
@or-sdk/transcripts1.2.5, 1.2.6, 1.2.7
@or-sdk/users3.8.1, 3.8.2, 3.8.3
@or-sdk/view-templates2.2.5, 2.2.6, 2.2.7
@or-sdk/views3.1.5, 3.1.6, 3.1.7
@or-sdk/web-search0.6.1, 0.6.2, 0.6.3
@ornikar/apollo-link-timeout1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.8, 1.4.9, 1.4.10, 1.4.11
@ornikar/babel-preset-base6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14
@ornikar/babel-preset-kitt-universal8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.0.11, 8.0.12
@ornikar/babel-preset-react6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14
@ornikar/browserslist-config8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10
@ornikar/commitlint-config8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.3.6, 8.3.7, 8.3.8, 8.3.9, 8.3.10, 8.3.11, 8.3.12
@ornikar/eslint-config24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10, 24.0.11, 24.0.12
@ornikar/eslint-config-babel24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10, 24.0.11, 24.0.12
@ornikar/eslint-config-babel-use13.2.1, 13.2.2, 13.2.3, 13.2.4, 13.2.5, 13.2.6, 13.2.7, 13.2.8, 13.2.9, 13.2.10, 13.2.11, 13.2.12
@ornikar/eslint-config-formatjs24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10
@ornikar/eslint-config-node12.2.1, 12.2.2, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10
@ornikar/eslint-config-react24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10, 24.0.11
@ornikar/eslint-config-typescript24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10
@ornikar/eslint-config-typescript-nestjs24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10, 24.0.11
@ornikar/eslint-config-typescript-react24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10, 24.0.11
@ornikar/eslint-plugin-neverthrow1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12
@ornikar/eslint-plugin-ornikar24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 24.0.10, 24.0.11
@ornikar/graphql-config1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9, 1.1.10, 1.1.11
@ornikar/intl-config10.0.2, 10.0.3, 10.0.4, 10.0.5, 10.0.6, 10.0.7, 10.0.8, 10.0.9
@ornikar/jest-config13.0.3, 13.0.4, 13.0.5, 13.0.6, 13.0.7, 13.0.8, 13.0.9, 13.0.10, 13.0.11, 13.0.12, 13.0.13
@ornikar/jest-config-react18.0.2, 18.0.3, 18.0.4, 18.0.5, 18.0.6, 18.0.7, 18.0.8, 18.0.9, 18.0.10, 18.0.11
@ornikar/jest-config-react-native17.0.2, 17.0.3, 17.0.4, 17.0.5, 17.0.6, 17.0.7, 17.0.8, 17.0.9, 17.0.10, 17.0.11, 17.0.12
@ornikar/jest-config-react-native-web12.0.3, 12.0.4, 12.0.5, 12.0.6, 12.0.7, 12.0.8, 12.0.9, 12.0.10, 12.0.11, 12.0.12, 12.0.13
@ornikar/kitt21.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11
@ornikar/lerna-config11.0.1, 11.0.2, 11.0.3, 11.0.4, 11.0.5, 11.0.6, 11.0.8, 11.0.9, 11.0.10, 11.0.11
@ornikar/monorepo-config14.3.2, 14.3.3, 14.3.4, 14.3.5, 14.3.6, 14.3.7, 14.3.8, 14.3.9, 14.3.10, 14.3.11, 14.3.12, 14.3.13
@ornikar/postcss-config9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.1.8, 9.1.9, 9.1.10, 9.1.11, 9.1.12
@ornikar/prettier-config9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10
@ornikar/prismic-components0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10, 0.0.11, 0.0.12
@ornikar/react-modern-calendar-datepicker3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.2.5, 3.2.6, 3.2.7, 3.2.8, 3.2.9, 3.2.10, 3.2.11
@ornikar/react-native-svg-transformer1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12
@ornikar/renovate-config9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.0.11, 9.0.12, 9.0.13
@ornikar/repo-config15.3.3, 15.3.4, 15.3.5, 15.3.6, 15.3.7, 15.3.8, 15.3.9, 15.3.10, 15.3.11, 15.3.12, 15.3.13
@ornikar/repo-config-react13.0.8, 13.0.9, 13.0.10, 13.0.11, 13.0.12, 13.0.13, 13.0.14, 13.0.15, 13.0.16, 13.0.17, 13.0.18, 13.0.19
@ornikar/repo-config-react-legacy-css15.1.2, 15.1.3, 15.1.4, 15.1.5, 15.1.6, 15.1.7, 15.1.8, 15.1.9, 15.1.10, 15.1.11, 15.1.12, 15.1.13
@ornikar/rollup-config11.1.2, 11.1.3, 11.1.4, 11.1.5, 11.1.6, 11.1.7, 11.1.8, 11.1.9, 11.1.10, 11.1.11, 11.1.12, 11.1.13
@ornikar/rollup-plugin-postcss2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15
@ornikar/slate-react-fork1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11
@ornikar/storybook-config12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.1.6, 12.1.7, 12.1.8, 12.1.9, 12.1.10
@ornikar/stylelint-config14.0.3, 14.0.5, 14.0.6, 14.0.7, 14.0.8, 14.0.9, 14.0.10, 14.0.11, 14.0.12, 14.0.13
@ornikar/typed-css-modules-loader0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.6, 0.8.7, 0.8.8, 0.8.9, 0.8.10, 0.8.11, 0.8.12
@ornikar/webpack-config12.0.2, 12.0.3, 12.0.4, 12.0.5, 12.0.6, 12.0.7, 12.0.8, 12.0.9, 12.0.10, 12.0.11, 12.0.12
picasso-plugin-hammer2.11.6
picasso-plugin-q2.11.6
picasso.js2.11.6
@picsart/ai-sdk3.32.2
@picsart/gen-ai2.55.11
pob-test-package-in-monorepo5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.2.6, 5.2.7, 5.2.8, 5.2.9, 5.2.10, 5.2.11, 5.2.12, 5.2.13, 5.2.14, 5.2.15, 5.2.16
pob-test-typescript-package-in-monorepo4.2.1, 4.2.2, 4.2.3, 4.2.4, 4.2.5, 4.2.6, 4.2.7, 4.2.8, 4.2.9, 4.2.10, 4.2.11, 4.2.12, 4.2.13, 4.2.14, 4.2.15, 4.2.16, 4.2.17
qlik-chart-modules1.1.1
qlik-modifiers0.10.1
qlik-object-conversion0.17.2
@qlik/api2.14.2
@qlik/browserslist-config3.0.2
@qlik/carbon-core2.1.1
@qlik/carboncopy1.1.6
@qlik/design-tokens1.3.13
@qlik/dts-bundler2.0.3
@qlik/embed-react2.5.3
@qlik/embed-runtime1.6.4
@qlik/embed-svelte1.1.4
@qlik/embed-web-components1.7.3
@qlik/eslint-config2.0.20
@qlik/eslint-config-base0.1.1
@qlik/eslint-config-react0.1.1
@qlik/eslint-config-svelte0.1.1
@qlik/eslint-config-vue0.1.1
@qlik/nebula-table-utils2.6.9
@qlik/oxfmt-config0.1.6
@qlik/oxlint-config0.7.2
@qlik/prettier-config1.0.3
@qlik/react-native-simple-grid1.5.5
@qlik/runtime-module-loader1.5.1
@qlik/sdk0.28.1
@qlik/sprout-design-docs1.0.2
@qlik/sprout-gesture0.0.13
@qlik/sprout-icons0.12.3
@qlik/sprout-react6.45.3
@qlik/sprout-react-table0.16.7
@qlik/tsconfig1.0.3
rwc-client0.29.10, 0.29.11, 0.29.12, 0.29.13, 0.29.14, 0.29.15, 0.29.16, 0.29.17, 0.29.18, 0.29.19
server-hemera-mongo0.0.12
@servicetitan/acquisition-functions5.22.1, 5.22.2, 5.22.3, 5.22.4, 5.22.5, 5.22.6, 5.22.7
@servicetitan/admin-layout2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9
@servicetitan/admin-sql-table1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20
@servicetitan/ajax-handlers38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/anvil-css-utilities14.5.4, 14.5.5, 14.5.6, 14.5.7, 14.5.8, 14.5.9, 14.5.10
@servicetitan/anvil-fonts14.5.4, 14.5.5, 14.5.6, 14.5.7, 14.5.8, 14.5.9, 14.5.10
@servicetitan/anvil-icon0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7
@servicetitan/anvil-icons14.5.4, 14.5.5, 14.5.6, 14.5.7, 14.5.8, 14.5.9, 14.5.10
@servicetitan/anvil-react0.11.3, 0.11.4, 0.11.5, 0.11.6, 0.11.7, 0.11.8, 0.11.9
@servicetitan/anvil-themes14.5.4, 14.5.5, 14.5.6, 14.5.7, 14.5.8, 14.5.9, 14.5.10
@servicetitan/anvil-token0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.4.6, 0.4.7
@servicetitan/anvil23.9.1, 3.9.2, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7
@servicetitan/anvil2-codemods0.11.2, 0.11.3, 0.11.4, 0.11.5, 0.11.6, 0.11.7, 0.11.8
@servicetitan/anvil2-ext-atlas4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.0.8
@servicetitan/anvil2-ext-charts0.2.4, 0.2.5, 0.2.6, 0.2.7, 0.2.8, 0.2.9, 0.2.10
@servicetitan/anvil2-ext-common0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.7.5, 0.7.6, 0.7.7
@servicetitan/anvil2-ext-mwv0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10, 0.0.11
@servicetitan/anvil2-illustrations1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8
@servicetitan/anvil2-mcp0.0.9, 0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15
@servicetitan/assist-ui2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7
@servicetitan/assist-utils1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8
@servicetitan/carto-charts-core0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8
@servicetitan/carto-charts-react0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8
@servicetitan/carto-charts-rn0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8
@servicetitan/carto-react-kit0.8.4, 0.8.5, 0.8.6, 0.8.7, 0.8.8, 0.8.9, 0.8.10
@servicetitan/carto-rn-kit0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16
@servicetitan/carto-tokens0.3.1, 0.3.2, 0.3.3, 0.3.4, 0.3.5, 0.3.6, 0.3.7
@servicetitan/component-usage28.5.1, 28.5.2, 28.5.3, 28.5.4, 28.5.5, 28.5.6, 28.5.7
@servicetitan/confirm41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/confirm-navigation41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/contentful0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9
@servicetitan/contentful-proxy1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18
@servicetitan/cp-api1.115.1, 1.115.2, 1.115.3, 1.115.4, 1.115.5, 1.115.6, 1.115.7
@servicetitan/cp-mfe1.115.1, 1.115.2, 1.115.3, 1.115.4, 1.115.5, 1.115.6, 1.115.7
@servicetitan/cp-mfe-dev1.115.1, 1.115.2, 1.115.3, 1.115.4, 1.115.5, 1.115.6, 1.115.7
@servicetitan/cp-react-hooks1.115.1, 1.115.2, 1.115.3, 1.115.4, 1.115.5, 1.115.6, 1.115.7
@servicetitan/cp-ui1.115.1, 1.115.2, 1.115.3, 1.115.4, 1.115.5, 1.115.6, 1.115.7
@servicetitan/culture41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/data-query41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/datadog-rum38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/datetime-utils41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/design-system14.5.4, 14.5.5, 14.5.6, 14.5.7, 14.5.8, 14.5.9, 14.5.10
@servicetitan/docs-anvil-uikit-contrib41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/docs-uikit38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/document-title2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.4.5, 2.4.6, 2.4.7
@servicetitan/dte-pdf-editor1.76.1, 1.76.2, 1.76.3, 1.76.4, 1.76.5, 1.76.6, 1.76.7
@servicetitan/dte-unlayer0.150.1, 0.150.2, 0.150.3, 0.150.4, 0.150.5, 0.150.6, 0.150.7
@servicetitan/eh-module-communication0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.2.7
@servicetitan/error-boundary38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/eslint-config38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/eslint-plugin38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/eslint-plugin-decorators-declare12.8.15, 12.8.16, 12.8.17, 12.8.18, 12.8.19, 12.8.20, 12.8.21
@servicetitan/eslint-plugin-folder-schema38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/eslint-plugin-mobx-612.8.15, 12.8.16, 12.8.17, 12.8.18, 12.8.19, 12.8.20
@servicetitan/eslint-plugin-processors-stub12.8.15, 12.8.16, 12.8.17, 12.8.18, 12.8.19, 12.8.20, 12.8.21
@servicetitan/examples1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.2.11
@servicetitan/feature-spotlight3.9.1, 3.9.2, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7
@servicetitan/folder-lint38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/forge0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7
@servicetitan/form41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/form-state41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/grid0.0.63, 0.0.64, 0.0.65, 0.0.66, 0.0.67, 0.0.68, 0.0.69
@servicetitan/hammer-icon1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7
@servicetitan/hammer-react1.42.2, 1.42.3, 1.42.4, 1.42.5, 1.42.6, 1.42.7, 1.42.8
@servicetitan/hammer-token3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.1.7
@servicetitan/hash-browser-router38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/help-center1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14
@servicetitan/html-sketchapp4.2.8, 4.2.9, 4.2.10, 4.2.11, 4.2.12, 4.2.13, 4.2.14
@servicetitan/install38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/intl7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7
@servicetitan/json-render-react0.4.6, 0.4.7, 0.4.8, 0.4.9, 0.4.10, 0.4.11, 0.4.12
@servicetitan/kendo-theme0.0.27, 0.0.28, 0.0.29, 0.0.30, 0.0.31, 0.0.32, 0.0.33
@servicetitan/ko-bridge38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/launchdarkly-service38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/lazy-module38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/ld-type-generator0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.2.7
@servicetitan/line-item-editor1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5, 1.5.6, 1.5.7
@servicetitan/link-item41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/log-service38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/marketing-direct-mail-components20.1.1, 20.1.2, 20.1.3, 20.1.4, 20.1.5, 20.1.6, 20.1.7
@servicetitan/marketing-email-components20.2.3, 20.2.4, 20.2.5, 20.2.6, 20.2.7, 20.2.8, 20.2.9
@servicetitan/marketing-form0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8
@servicetitan/marketing-global-route1.14.1, 1.14.2, 1.14.3, 1.14.4, 1.14.5, 1.14.6, 1.14.7
@servicetitan/marketing-integration-widgets1.0.40, 1.0.41, 1.0.42, 1.0.43, 1.0.44, 1.0.45, 1.0.46
@servicetitan/marketing-route1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7
@servicetitan/marketing-ui9.3.1, 9.3.2, 9.3.3, 9.3.4, 9.3.5, 9.3.6, 9.3.7
@servicetitan/marketing-widgets1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7
@servicetitan/measure-sheet-data2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7
@servicetitan/mfe-quick-actions0.5.49, 0.5.50, 0.5.51, 0.5.52, 0.5.53, 0.5.54, 0.5.55
@servicetitan/micro-frontend0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10
@servicetitan/microfront0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8
@servicetitan/microfront-auth0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10, 0.0.11
@servicetitan/microfront-tests0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.0.16, 0.0.17
@servicetitan/microfront-utils1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7
@servicetitan/modularpayments-webfields1.0.53, 1.0.54, 1.0.55, 1.0.56, 1.0.57, 1.0.58, 1.0.59
@servicetitan/moneyout-api-client1.29.1, 1.29.2, 1.29.3, 1.29.4, 1.29.5, 1.29.6, 1.29.7
@servicetitan/mpa-components2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 2.5.6, 2.5.7
@servicetitan/navigation14.1.1, 14.1.2, 14.1.3, 14.1.4, 14.1.5, 14.1.6, 14.1.7
@servicetitan/notifications41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/onboarding-ui18.5.1, 18.5.2, 18.5.3, 18.5.4, 18.5.5, 18.5.6, 18.5.7
@servicetitan/quick-actions1.15.2, 1.15.3, 1.15.4, 1.15.5, 1.15.6, 1.15.7, 1.15.8
@servicetitan/react-hooks7.7.1, 7.7.2, 7.7.3, 7.7.4, 7.7.5, 7.7.6, 7.7.7
@servicetitan/react-ioc38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/responsive6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7
@servicetitan/restrict-imports38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/schema-comparison0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8, 0.1.9
@servicetitan/skeleton9.2.4, 9.2.5, 9.2.6, 9.2.7, 9.2.8, 9.2.9, 9.2.10
@servicetitan/standalone-core-feature-gates1.11.4, 1.11.5, 1.11.6, 1.11.7, 1.11.8, 1.11.9, 1.11.10
@servicetitan/standalone-feature-flags2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6, 2.3.7, 2.3.8
@servicetitan/standalone-root1.11.3, 1.11.4, 1.11.5, 1.11.6, 1.11.7, 1.11.8, 1.11.9
@servicetitan/standalone-tm-api1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7
@servicetitan/standalone-ui2.2.4, 2.2.5, 2.2.6, 2.2.7, 2.2.8, 2.2.9, 2.2.10
@servicetitan/startup38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/startup-jest2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.2.5, 2.2.6, 2.2.7
@servicetitan/startup-mfe-compat0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5, 0.5.6, 0.5.7
@servicetitan/startup-utils38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/stylelint-config38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/suppress-warnings38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/table41.3.1, 41.3.2, 41.3.3, 41.3.4, 41.3.5, 41.3.6, 41.3.7
@servicetitan/tanstack-query-mobx6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7
@servicetitan/temporal-lite3.4.1, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.4.6, 3.4.7
@servicetitan/testing-library6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7
@servicetitan/thoughtspot-theme1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7
@servicetitan/time-zones3.8.1, 3.8.2, 3.8.3, 3.8.4, 3.8.5, 3.8.6, 3.8.7
@servicetitan/titan-chat-ui7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9
@servicetitan/titan-chat-ui-anvil29.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7
@servicetitan/titan-chat-ui-common9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7
@servicetitan/titan-chat-ui-cypress2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9
@servicetitan/titan-chatbot-api9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7
@servicetitan/titan-chatbot-client2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9
@servicetitan/titan-chatbot-ui7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9
@servicetitan/titan-chatbot-ui-anvil29.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7
@servicetitan/titan-chatbot-ui-cypress9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7
@servicetitan/tokens12.9.1, 12.9.2, 12.9.3, 12.9.4, 12.9.5, 12.9.6, 12.9.7
@servicetitan/toolbelt-shared-registry1.14.1, 1.14.2, 1.14.3, 1.14.4, 1.14.5, 1.14.6, 1.14.7
@servicetitan/uikit-docs22.11.1, 22.11.2, 22.11.3, 22.11.4, 22.11.5, 22.11.6, 22.11.7
@servicetitan/unit-tests0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8
@servicetitan/va-mfe-loader1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7
@servicetitan/web-components38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7
@servicetitan/widget-platform5.6.1, 5.6.2, 5.6.3, 5.6.4, 5.6.5, 5.6.6, 5.6.7
@servicetitan/widget-platform-monolith5.6.1, 5.6.2, 5.6.3, 5.6.4, 5.6.5, 5.6.6, 5.6.7
sn-listbox0.3.3
@thiennq/docs-viewer1.6.2, 1.6.3, 1.6.4
tslint-folder-schema1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21
@umacloud/cli-darwin-arm641.0.74
@umacloud/cli-darwin-x641.0.74
@umacloud/cli-linux-arm641.0.74
@umacloud/cli-linux-musl-arm641.0.74
@umacloud/cli-linux-musl-x641.0.74
@umacloud/cli-linux-x641.0.74
@umacloud/cli-win32-x641.0.74
@umacloud/knowledge1.0.74
umadev1.0.74
verdaccio-okta-oauth38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7, 38.1.8, 38.1.9, 38.1.10, 38.1.11, 38.1.12, 38.1.13, 38.1.14, 38.1.15, 38.1.16
verdaccio-tarball-local-storage38.1.1, 38.1.2, 38.1.3, 38.1.4, 38.1.5, 38.1.6, 38.1.7, 38.1.8, 38.1.9, 38.1.10, 38.1.11, 38.1.12, 38.1.13, 38.1.14, 38.1.15, 38.1.16
workbench-browser-server0.0.2
@workbench-stack/core3.9.8

Observed between 09:40 and 13:20 UTC on 4 August 2026. The list should be treated as a floor, not a ceiling — the campaign was ongoing at the time of publication.

What to Do This Week

Immediate — first 24 hours

  • Search every dependency record across the organisation for the names and versions above, including indirect dependencies.
  • Treat any match as a confirmed compromise of that machine or build job, not as a possibility to investigate later.
  • Roll back and pin to the last known-good versions rather than relying on automatic version ranges.
  • Remove the persistence watcher before rotating credentials on affected developer machines, since it is specifically designed to react to token revocation.

Within the week

  • Rotate everything that was in reach: publishing tokens, cloud provider credentials, deployment keys, container platform service accounts, secret store access, personal access tokens and any credentials sitting in environment files.
  • Review cloud audit logs for use of those credentials from unfamiliar locations during and after the exposure window.
  • Audit your own published software for releases nobody on your team authorised — this is how second-wave victims discovered they had become distributors.
  • Rebuild affected environments cleanly, with automatic install scripts disabled.

The Controls That Would Have Stopped It

  • Turn off automatic install scripts in build pipelines. The entire attack depends on code executing during installation. Disable it by default and allow it only for the small number of dependencies that genuinely require it. This alone neutralises the whole class of attack.
  • Adopt a minimum age for new dependency versions. Every malicious version here was consumed within minutes to hours of release, and the registry removed them within roughly two hours. A three to seven day cooling-off period on new versions is a cheap, high-yield control now supported natively by the major package managers.
  • Control outbound traffic from build systems. Build agents should not be free to fetch arbitrary runtimes or contact arbitrary destinations. Reputation-based blocking is not enough here, because the download came from a well-known, legitimate source.
  • Stop treating provenance as authorisation. Pair signature verification with change detection on the release itself: newly added install hooks, new files being shipped and edits to release tooling are all high-signal anomalies.
  • Harden maintainer and developer accounts. Phishing-resistant multi-factor authentication, short-lived scoped tokens and mandatory review before code reaches a release branch would each, independently, have broken this chain.
  • Govern AI assistant and editor configuration like code. This payload used those configuration folders for persistence. Inventory them, pin them, and alert on unexpected changes. Expect this technique to become routine.

What Boards Should Take From This

Three conclusions are worth carrying into your next risk discussion. First, third-party software risk is no longer only about the vendors you contract with — it now includes the thousands of unpaid open source components those vendors and your own teams pull in automatically. Second, the speed of automated propagation means detection and response windows must be measured in minutes, which requires continuous inventory rather than periodic audit. Third, cryptographic assurances answer the question “was this built from that source?” — they do not answer “should that source change have existed?”. That second question is a governance problem, and it is where the remaining exposure sits.

A continuously maintained, machine-readable inventory of every component in every application — including the ones you bought — is the difference between answering “are we exposed?” in ten minutes and answering it in ten days. In an incident that reached 444 packages in four hours, that gap is the entire risk.
Frequently Asked Questions
1Was this caused by a weak or stolen npm password?
No. The entry point was the maintainer's GitHub account, not their npm publishing token. Once inside GitHub, the attacker pushed a tampered release and let the project's own trusted, automated release pipeline do the publishing. That is why the malicious versions looked perfectly legitimate to every automated check.
2Our tooling verifies package provenance and signatures. Why did that not help?
Provenance proves which source commit was built. It does not prove that the commit was authorised. Because the attacker poisoned the source and then triggered the genuine release workflow, every malicious version carried a valid attestation. Signature and provenance checks alone would have approved all of them.
3How do we know in practical terms whether we were exposed?
Three places: your lockfiles (search for the affected name and version pairs), your CI/CD logs for installs during the exposure window, and developer laptops. The malicious files remain on disk after installation, which makes after-the-fact detection straightforward.
4What is the realistic business impact if we installed one of these versions?
Assume that every secret available to that machine or build job was read and sent out — cloud keys, deployment credentials, publishing tokens, API keys. The most serious downstream risk is that your own software releases could then be tampered with using your own credentials, exactly as happened to the second-wave victims.
5Why does the number of affected versions look so large compared with the number of packages?
The worm did not simply publish one new version per victim. It republished long histories of previous versions with the malicious payload attached, which is how 444 packages produced 2,212 compromised versions.
6What single control would have blocked this most cheaply?
Disabling automatic install scripts in CI. The entire attack depends on code running automatically during installation. With install scripts turned off, the malicious files would have sat on disk doing nothing.
7Should we delay adopting new package versions as a policy?
Yes. Every malicious version here was consumed within minutes to hours of publication, and the registry removed them within about two hours. A three to seven day minimum age policy on new dependency versions would have prevented almost all automatic exposure, at very little engineering cost.
8We revoked our GitHub token already. Is that enough?
Be careful. On infected developer machines the malware installs a watcher designed to trigger further attacker activity precisely when the stolen token is revoked. Remove that watcher first, then rotate credentials from a separate, clean machine.