Impact analysis of recent NPM Supply Chain Attack

Incident Report for Skedda

Resolved

We have received confirmation from all our relevant sub-processors that they have not been affected, so we are now marking this as resolved. We will continue to track activity across the npm ecosystem with our partners to ensure deployments on Skedda remain secure by default.
Posted Sep 10, 2025 - 21:36 UTC

Investigating

The Skedda security team has conducted an internal analysis of the packages compromised by the recent NPM supply chain attack (https://en.wikipedia.org/wiki/Npm#:~:text=%5B40%5D-,September%202025%20Supply%20Chain%20Attack,-%5Bedit%5D).

Skedda can confirm that there are no cases of a compromised package in use on Skedda's own software stack. Skedda is not currently directly depending on any of the affected package versions.

No action is required at this time.

We are currently in the process of confirming that the services of our relevant set of partners/sub-processors has likewise been unaffected. We will provide an update here once these investigations have completed. We will continue to track activity across the npm ecosystem with our partners to ensure deployments on Skedda remain secure by default.
Posted Sep 10, 2025 - 08:04 UTC