Home / Companies / Mintlify / Blog / Post Details
Content Deep Dive

Impact of SHA1-Hulud: The Second Coming on the Mintlify CLI

Blog post from Mintlify

Post Details
Company
Date Published
Author
Han Wang
Word Count
697
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

On November 24, 2025, the Mintlify CLI was exposed to a supply chain attack, SHA1-Hulud: The Second Coming, which involved compromised npm dependencies and impacted over 25,000 repositories. The vulnerability arose from flexible version specifications in dependency packages used by the CLI, leading to the automatic installation of malicious versions. Within six hours, Mintlify detected, addressed the issue by releasing a secure version (4.2.210), deprecated affected versions, and verified that hosted services were unaffected due to locked dependency versions. Users who installed the CLI during the attack are advised to update immediately, clear caches, check for suspicious activity, and rotate potentially exposed credentials. As a preventive measure, Mintlify has strengthened its dependency pinning and alerting protocols to better handle future supply chain security incidents.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.