pnpm Package-Manager Supply-Chain Advisory Batch

Confirmed
Discovered Jun 27, 2026

pnpm disclosed a cluster of package-manager vulnerabilities affecting lockfile integrity, Git dependency fetching, repository registry configuration, patch application, and symlink creation; responders should inventory vulnerable pnpm versions and review credential-bearing install paths.

2
Affected Packages
18
Observables
6
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 27, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Direct source

Affected Software

2 of 2 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
pnpm < 10.34.2npmunknownMalicious90%Direct source
pnpm >= 11.0.0npmunknownMalicious90%Direct source

IOC Clipboard

18 IOCs
domaincodeload.github.com
urlhttps://github.com/pnpm/pnpm/security/advisories/GHSA-hg3w-7f8c-63hp
urlhttps://github.com/pnpm/pnpm/security/advisories/GHSA-54hh-g5mx-jqcp
urlhttps://github.com/pnpm/pnpm/security/advisories/GHSA-q6j5-fjx5-2mc3
urlhttps://github.com/pnpm/pnpm/security/advisories/GHSA-p4xf-rf54-rj3x
urlhttps://github.com/pnpm/pnpm/security/advisories/GHSA-hwx4-2j3j-g496
urlhttps://github.com/pnpm/pnpm/security/advisories/GHSA-cjhr-43r9-cfmw
file_pathpackage.json
file_pathpnpm-lock.yaml
file_pathpnpm-workspace.yaml
file_path.npmrc
file_path*.patch
file_path.github/workflows
commandpnpm install
commandpnpm add
commandpnpm view
commandpnpm patch
commandgit fetch

Provenance & Sources

6 of 6 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Direct sourcedirect95%1https://github.com/pnpm/pnpm/security/advisories/GHSA-hg3w-7f8c-63hp
Direct sourcedirect95%1https://github.com/pnpm/pnpm/security/advisories/GHSA-54hh-g5mx-jqcp
Direct sourcedirect95%1https://github.com/pnpm/pnpm/security/advisories/GHSA-q6j5-fjx5-2mc3
Direct sourcedirect95%1https://github.com/pnpm/pnpm/security/advisories/GHSA-p4xf-rf54-rj3x
Primary researchprimary research95%1https://github.com/pnpm/pnpm/security/advisories/GHSA-3qhv-2rgh-x77r
Correlated sourcecorrelated80%1https://github.com/advisories?query=pnpm