Skip to content

Commit 6ed981f

Browse files
author
github-actions
committed
Assign IDs
1 parent 4a5b28f commit 6ed981f

File tree

1,370 files changed

+18362
-37116
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,370 files changed

+18362
-37116
lines changed

osv/malicious/npm/8x8-developer-docs/MAL-0000-amazon-inspector-830ce990639483b2.json

Lines changed: 0 additions & 41 deletions
This file was deleted.

osv/malicious/npm/8x8-developer-docs/MAL-2026-1379.json

Lines changed: 18 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
2-
"modified": "2026-03-19T12:23:17Z",
2+
"modified": "2026-03-23T05:16:24Z",
33
"published": "2026-03-13T02:21:45Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2026-1379",
66
"aliases": [
77
"GHSA-89hj-xp64-rgvm"
88
],
99
"summary": "Malicious code in 8x8-developer-docs (npm)",
10-
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (8653dd8d9372dda6122b5ac738ed053d7750f453b48598cc35396b3044afa348)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n",
10+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (830ce990639483b2f7a9ea4e000d63c831e0d58c94e718a1a20add6885cb93ef)\nThe package 8x8-developer-docs was found to contain malicious code.\n\n## Source: ghsa-malware (8653dd8d9372dda6122b5ac738ed053d7750f453b48598cc35396b3044afa348)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n",
1111
"affected": [
1212
{
1313
"package": {
@@ -45,6 +45,13 @@
4545
}
4646
],
4747
"credits": [
48+
{
49+
"name": "Amazon Inspector",
50+
"type": "FINDER",
51+
"contact": [
52+
"actran@amazon.com"
53+
]
54+
},
4855
{
4956
"name": "ReversingLabs",
5057
"type": "FINDER",
@@ -81,6 +88,15 @@
8188
"versions": [
8289
"2.0.0"
8390
]
91+
},
92+
{
93+
"source": "amazon-inspector",
94+
"sha256": "830ce990639483b2f7a9ea4e000d63c831e0d58c94e718a1a20add6885cb93ef",
95+
"import_time": "2026-03-23T05:14:30.457420594Z",
96+
"modified_time": "2026-03-23T05:11:41Z",
97+
"versions": [
98+
"2.0.0"
99+
]
84100
}
85101
]
86102
}

osv/malicious/npm/@3stripes/api-client/MAL-0000-amazon-inspector-1644f08d12a97a4d.json

Lines changed: 0 additions & 41 deletions
This file was deleted.

osv/malicious/npm/@3stripes/api-client/MAL-2026-1424.json

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
{
2-
"modified": "2026-03-15T05:45:44Z",
2+
"modified": "2026-03-23T05:16:24Z",
33
"published": "2026-03-15T05:45:44Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2026-1424",
66
"summary": "Malicious code in @3stripes/api-client (npm)",
7-
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (a25a3f6f0b4ff00af8eca4dcea0bfdb698f071423a6b30b1b62a440b71137688)\nThe OpenSSF Package Analysis project identified '@3stripes/api-client' @ 999.0.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1644f08d12a97a4daeeca3e4195d91585bdbe1a8c2085fa918a92427cf1ee99f)\nThe package @3stripes/api-client was found to contain malicious code.\n\n## Source: ossf-package-analysis (a25a3f6f0b4ff00af8eca4dcea0bfdb698f071423a6b30b1b62a440b71137688)\nThe OpenSSF Package Analysis project identified '@3stripes/api-client' @ 999.0.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
88
"affected": [
99
{
1010
"package": {
@@ -17,6 +17,13 @@
1717
}
1818
],
1919
"credits": [
20+
{
21+
"name": "Amazon Inspector",
22+
"type": "FINDER",
23+
"contact": [
24+
"actran@amazon.com"
25+
]
26+
},
2027
{
2128
"name": "OpenSSF: Package Analysis",
2229
"type": "FINDER",
@@ -29,10 +36,19 @@
2936
"database_specific": {
3037
"malicious-packages-origins": [
3138
{
39+
"source": "ossf-package-analysis",
40+
"sha256": "a25a3f6f0b4ff00af8eca4dcea0bfdb698f071423a6b30b1b62a440b71137688",
3241
"import_time": "2026-03-15T05:56:20.841110973Z",
3342
"modified_time": "2026-03-15T05:45:44Z",
34-
"sha256": "a25a3f6f0b4ff00af8eca4dcea0bfdb698f071423a6b30b1b62a440b71137688",
35-
"source": "ossf-package-analysis",
43+
"versions": [
44+
"999.0.2"
45+
]
46+
},
47+
{
48+
"source": "amazon-inspector",
49+
"sha256": "1644f08d12a97a4daeeca3e4195d91585bdbe1a8c2085fa918a92427cf1ee99f",
50+
"import_time": "2026-03-23T05:14:33.837363085Z",
51+
"modified_time": "2026-03-23T05:11:41Z",
3652
"versions": [
3753
"999.0.2"
3854
]

osv/malicious/npm/@3stripes/auth/MAL-0000-amazon-inspector-152509a4bd82adf6.json

Lines changed: 0 additions & 41 deletions
This file was deleted.

osv/malicious/npm/@3stripes/auth/MAL-2026-1425.json

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
{
2-
"modified": "2026-03-15T05:45:45Z",
2+
"modified": "2026-03-23T05:16:24Z",
33
"published": "2026-03-15T05:45:45Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2026-1425",
66
"summary": "Malicious code in @3stripes/auth (npm)",
7-
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (6dfef2aa5b1531e49858972a00975d216023431edb51a77bfb48daff095f6b58)\nThe OpenSSF Package Analysis project identified '@3stripes/auth' @ 999.0.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (152509a4bd82adf6364c22476faa63746b5ddc6649dd64a7fdf96ff5e67ebc13)\nThe package @3stripes/auth was found to contain malicious code.\n\n## Source: ossf-package-analysis (6dfef2aa5b1531e49858972a00975d216023431edb51a77bfb48daff095f6b58)\nThe OpenSSF Package Analysis project identified '@3stripes/auth' @ 999.0.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
88
"affected": [
99
{
1010
"package": {
@@ -17,6 +17,13 @@
1717
}
1818
],
1919
"credits": [
20+
{
21+
"name": "Amazon Inspector",
22+
"type": "FINDER",
23+
"contact": [
24+
"actran@amazon.com"
25+
]
26+
},
2027
{
2128
"name": "OpenSSF: Package Analysis",
2229
"type": "FINDER",
@@ -29,10 +36,19 @@
2936
"database_specific": {
3037
"malicious-packages-origins": [
3138
{
39+
"source": "ossf-package-analysis",
40+
"sha256": "6dfef2aa5b1531e49858972a00975d216023431edb51a77bfb48daff095f6b58",
3241
"import_time": "2026-03-15T05:56:20.962865244Z",
3342
"modified_time": "2026-03-15T05:45:45Z",
34-
"sha256": "6dfef2aa5b1531e49858972a00975d216023431edb51a77bfb48daff095f6b58",
35-
"source": "ossf-package-analysis",
43+
"versions": [
44+
"999.0.2"
45+
]
46+
},
47+
{
48+
"source": "amazon-inspector",
49+
"sha256": "152509a4bd82adf6364c22476faa63746b5ddc6649dd64a7fdf96ff5e67ebc13",
50+
"import_time": "2026-03-23T05:14:08.409373092Z",
51+
"modified_time": "2026-03-23T05:11:41Z",
3652
"versions": [
3753
"999.0.2"
3854
]

osv/malicious/npm/@3stripes/common/MAL-0000-amazon-inspector-2cf6f6a1fb0e79c7.json

Lines changed: 0 additions & 41 deletions
This file was deleted.

osv/malicious/npm/@3stripes/common/MAL-2026-1426.json

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
{
2-
"modified": "2026-03-15T05:46:19Z",
2+
"modified": "2026-03-23T05:16:24Z",
33
"published": "2026-03-15T05:46:19Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2026-1426",
66
"summary": "Malicious code in @3stripes/common (npm)",
7-
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (c6aa69228a321e8dac046c1953e5930f768b1166eca49861d4d90bc54f96e6f6)\nThe OpenSSF Package Analysis project identified '@3stripes/common' @ 999.0.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2cf6f6a1fb0e79c716386545df6b4a1e4df689bf6b35e741c28150cc3fad072a)\nThe package @3stripes/common was found to contain malicious code.\n\n## Source: ossf-package-analysis (c6aa69228a321e8dac046c1953e5930f768b1166eca49861d4d90bc54f96e6f6)\nThe OpenSSF Package Analysis project identified '@3stripes/common' @ 999.0.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
88
"affected": [
99
{
1010
"package": {
@@ -17,6 +17,13 @@
1717
}
1818
],
1919
"credits": [
20+
{
21+
"name": "Amazon Inspector",
22+
"type": "FINDER",
23+
"contact": [
24+
"actran@amazon.com"
25+
]
26+
},
2027
{
2128
"name": "OpenSSF: Package Analysis",
2229
"type": "FINDER",
@@ -29,10 +36,19 @@
2936
"database_specific": {
3037
"malicious-packages-origins": [
3138
{
39+
"source": "ossf-package-analysis",
40+
"sha256": "c6aa69228a321e8dac046c1953e5930f768b1166eca49861d4d90bc54f96e6f6",
3241
"import_time": "2026-03-15T05:56:21.196971686Z",
3342
"modified_time": "2026-03-15T05:46:19Z",
34-
"sha256": "c6aa69228a321e8dac046c1953e5930f768b1166eca49861d4d90bc54f96e6f6",
35-
"source": "ossf-package-analysis",
43+
"versions": [
44+
"999.0.2"
45+
]
46+
},
47+
{
48+
"source": "amazon-inspector",
49+
"sha256": "2cf6f6a1fb0e79c716386545df6b4a1e4df689bf6b35e741c28150cc3fad072a",
50+
"import_time": "2026-03-23T05:14:18.518770026Z",
51+
"modified_time": "2026-03-23T05:11:41Z",
3652
"versions": [
3753
"999.0.2"
3854
]

0 commit comments

Comments
 (0)