Neptune Software Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Welcome to Neptune Software's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.

Documents

REPORTSPentest Report
Infraserv Höchst
Bell Food Group AG
HAUNI
Forsvaret
BIRKENSTOCK
Fonterra
United Utilities
Statkraft
Vattenfall
RUST-OLEUM Europe
NZ Defence Force
Secil
Dussmann Group
Elkjøp
Safran Vectronix
Hitachi Rail Europe
Johnson & Johnson
Knowledge Base (FAQ)
  • What is your product architecture, including security?
  • How do you ensure business continuity and disaster recovery?
  • How can customers report a security vulnerability?
  • How do you handle data breaches or security incidents?
  • How is data encrypted in transit and at rest?
View more
Trust Center Updates

Neptune Software not affected by the NPM supply chain attack

Copy link
Vulnerabilities

Neptune Software not affected by the NPM supply chain attack

What happened?

On September 8, 2025, attackers compromised the NPM account of a well-known developer through a phishing campaign. They published malicious versions of 18 popular Node.js packages (including chalk, debug, ansi-styles and others) with a hidden crypto-clipper payload. The malware silently replaced cryptocurrency wallet addresses in web3/browser contexts, redirecting funds to attacker-controlled wallets.

Why Neptune DXP Open Edition is safe?

While Neptune DXP Open Edition is based on Node.js, the corresponding Node.js project—including its dependencies—and bundles everything into a standalone executable at build time. This means:

The executable contains the exact dependency versions specified when the build was created.
Once built, the app no longer fetches code from NPM at runtime.
Therefore, any malicious package versions never entered our binaries.

What you should do?

Beyond the packaged Neptune DXP Open Edition binary the platform supports the usage of custom installed NPM modules for script logic development.

The compromised packages were online only for a few hours at most, drastically reducing the likelihood that you catched any of these. Nevertheless make sure to check your list of custom NPM modules (cockpit app NPM Modules) against the list of compromised packages and their versions.

References
https://www.stepsecurity.io/blog/20-popular-npm-packages-compromised-chalk-debug-strip-ansi-color-convert-wrap-ansi

If you need help using this Trust Center, please contact us.
Contact support
If you think you may have discovered a vulnerability, please send us a note.
Report issue