5 ms·
NPM stylus package contained malicious code and was removed from the registry
- yoavfr 1y agoA quick workaround if you're affected by a deep dependency and don't rely on stylus directly - add `"overrides": {"stylus": "0.0.1-security"}` to your package.json
- dmitryeu 1y agoWork around the issue by installing directly from GitHub using package.json overrides: ``` "overrides": { "stylus": "github:stylus/stylus#0.64.0" } ``` Maintainer @iChenLei reports they are negotiating with npm officials to restore access: https://github.com/stylus/stylus/issues/2938 https://github.com/stylus/stylus/issues/2938
- maury91 1y agoThis advisory is pointing to the stylus package https://github.com/advisories/GHSA-fh4q-jc76-r59p https://github.com/advisories/GHSA-fh4q-jc76-r59p I'm still unsure if it's a mistake on NPM side or if stylus and the authors are compromised
- clncy 1y agoIt's so hard to triage this when no justification has been provided for the advisory. Was the GHSA released in response to npm pulling the package, or vice versa? Many suggestions for workarounds, but if the GHSA is indeed accurate (all versions affected) then that seems unwise.
- maury91 1y agoAlso if all the versions are affected this malware is in stylus since 2010. Honestly, it sounds improbable to me that a malware exists unnoticed in open source software for 15 years. However, even if improbable it's better to play safe and just override the installation of stylus ( especially if you are not using it ) with an empty package until more information is released
- clncy 1y agoI agree that it seems very improbable. The only possible malicious scenario I can imagine is that the Github repo is clean, but npm creds have been compromised.
- wut42 1y agoThe package was pulled at: 2025-07-23T03:03:01.239Z And the GHSA advisory: 2025-07-23T03:03:56Z So the GHSA was released after the pull (by a minute).
- kaelwd 1y agoRemoving the entire package is pretty unusual, normally it's only specific compromised versions.
- maury91 1y agoThe advisory says all the versions are affected ">= 0" https://github.com/advisories/GHSA-fh4q-jc76-r59p https://github.com/advisories/GHSA-fh4q-jc76-r59p
- bapak 1y agoOnce again proof that advisories are full of etc. Stylus has been around for 15 (FIFTEEN) years. Obviously the "vulnerability" is a lie. Npm is known to cause huge losses of money for developers and companies around the world when they pull things like this, blindly applying advisories.
- maury91 1y agoFrom how is unfolding the most probable outcome is that one of the maintainer is compromised ( Ponya ), all of the packages he contributed to have been marked
- wut42 1y agoThat could track but people in the GitHub issue ( https://github.com/stylus/stylus/issues/2938#issuecomment-3105673072 https://github.com/stylus/stylus/issues/2938#issuecomment-31... ) have found that no "other" version of Stylus has been released.
- maury91 1y agoIt may simply be Github and NPM going nuclear and just flagging everything just in case
- wut42 1y agoCould be! Other comments (~~can't find them now as the issue got full of useless comments~~ e.g. https://github.com/stylus/stylus/issues/2938#issuecomment-3106305593 https://github.com/stylus/stylus/issues/2938#issuecomment-31...) also noted that the GHSA bot have nuked a lot of other npm packages since days or weeks in the same fashion, so it could also be an AI scanner going full full nuclear.
- maury91 1y agoAgree it would be nice if people would stop posting "help! how can I fix this?" and "I fixed it by doing X", they were valid comments at the beginning, but now more than half of the comments are just these two
- delfinom 1y agoWell, how else do people who never read and understood the tools they are using get help? Coding boot camps only teach so much lol.
- bapak 1y agoThe title is wrong. There's no proof of compromise. There are no releases of the package since October. Apparently one of the long-time maintainers has pushed other compromised packages, so npm just nuked all the packages he had access to, whether they were compromised or not.
- sensanaty 1y agoMan I thought I was going crazy. My staging build was failing and I saw that stylus was the culprit. Running `npm why stylus`, `npm ls --all stylus`, and other variants of these two commands consistently returned nothing, but I can see it in my lockfile if I run `grep -R stylus package-lock.json`. Even running `npm audit | grep stylus` returned nothing! Which I think is pretty crazy considering the package itself has been overwritten by NPM to include a 0 context scary "Security holding package" thing. Surely this sort of thing should show up in the `audit` results?
- nice_2 1y ago[dead]
- kontercola 1y agoMy workaround: Add this on your package.json on the end of file bevor last }: }, "overrides": { "stylus": "0.0.1-security" }
- okcdz 1y agoIt seems this doesn't work. The package is empty, it can't function. It makes the world stop, which is terrible!
- dale_lakes 1y agoRandom internet person: Do not do this ^ . Wait for the package to be restored by npmjs, or use the workaround in the pinned issue on the stylus repo.
- finchisko 1y agoColleague of mine. Pointed out that github advisory had many new malware reports in last few days. All looking same. Looks suspicious if you ask me. Maybe somebody hacked the github advisory db? https://github.com/advisories?page=1&query=type%3Amalware https://github.com/advisories?page=1&query=type%3Amalware
- rupoJS 1y ago[dead]
- righthand 1y agoI have to say NPM packaging is terrible. I probably spend 1 month of the year fiddling with upgrading packages due to security issues. That is just the amount of time I spend on my repos alone. All of this extra effort to avoid code signing and making package owners accountable. It seems like every week there is a new security high sev ticket to fix some webpack dependency. Not to mention that even if you do successfully run “npm audit fix” (—force), Npm may not update to the correct new version and will often downgrade packages many many many versions. The error messages that Npm spits out have always frightened junior devs too. I can’t wait for that whole ecosystem to be replaced.
- sensanaty 1y agoThe crazy thing is that `npm audit` doesn't even list `stylus` here, at least not in my repos. Despite them literally overtaking the damn package on the registry for a *security issue*.
- righthand 1y agoIt gets even better, Dependabot will spam you severities of it’s own that don’t appear in audit. So you probably need to carefully audit the changes from two data sources and the security ticket ends up being 2+ merge requests.
- vdupras 1y agoI have a question. I'm curious. I see two comments here on this subject, complaining about the churn of dealing with security advisories. Sure, it's churn. ... but isn't this problem dwarfed by the implications of having used a compromised package? Presumably, if the project you work on has a compromised dependency, it means you've ran it on your development machine. Presumably, you might have a couple of secrets (private keys, AWS credentials and other whatnots) lying around, which might have leaked to a malicious actor. Wouldn't you need to review all the development, staging and production machines for all your projects and rotate secrets everywhere? Wouldn't it be, by far, the biggest churn involved, so much that mentioning "npm audit" difficulties not worth mentioning at all, because of the ridiculous comparison in effort magnitude?
- borplk 1y agoDoes anyone know what the malicious code was and what it did?
- dale_lakes 1y agoThe malicious code had nothing to do with the stylus package. One of the maintainers of stylus published malicious code in another package, and GitHub / npmjs response was to nuke ALL packages that he was a maintainer of, including stylus.
- silverwind 1y agoThe sensible action would be to remove only the malicious packages and suspend that account.
- jstasiak 1y agoThe package has now been restored/reinstated: https://web.archive.org/web/20250723155529/https://www.npmjs.com/package/stylus https://web.archive.org/web/20250723155529/https://www.npmjs... This has been reflected in a recent edit and comments here: https://github.com/stylus/stylus/issues/2938 https://github.com/stylus/stylus/issues/2938 No updates to the security advisory at this time: https://web.archive.org/web/20250723155624/https://github.com/advisories/GHSA-fh4q-jc76-r59p https://web.archive.org/web/20250723155624/https://github.co...
- veidr 1y agoThis advisory has been withdrawn because the stylus npm package is not malware. It took a while, but we now have some clarity.