Skip to content

Commit 92f3fa2

Browse files
author
github-actions
committed
Ingest OSV - Cloud Storage
1 parent 1599c8d commit 92f3fa2

File tree

5 files changed

+169
-1
lines changed

5 files changed

+169
-1
lines changed

config/start-keys.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ kam193:
55
pypi/packages/pentest/osv/: 0d65fa30569acb74a4cd2f6968297f9cf794b510
66
pypi/packages/probably_pentest/osv/: d85355ff7c5f46aa548621c0248747e10eee650a
77
ossf-package-analysis:
8-
confident/: confident/20260321/132849-npm-characterai-poc-1.0.0.json
8+
confident/: confident/20260321/183346-npm-uipathisfun-1.0.33.json
99
reversing-labs:
1010
RLMA-: RLMA-2026-01666.json
1111
RLUA-: RLUA-2026-01611.json
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-22T05:55:53Z",
3+
"published": "2026-03-22T05:55:53Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @mesh-components/card (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@mesh-components/card' @ 99999.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@mesh-components/card"
13+
},
14+
"versions": [
15+
"99999.0.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "40f7a614db4f6d3c3a128c80f24ff11581c968a84522dd84308acafec09f569a",
34+
"import_time": "2026-03-22T06:22:29.577336929Z",
35+
"modified_time": "2026-03-22T05:55:53Z",
36+
"versions": [
37+
"99999.0.0"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-22T05:55:36Z",
3+
"published": "2026-03-22T05:55:36Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @mesh-components/customthemeprovider (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@mesh-components/customthemeprovider' @ 99999.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@mesh-components/customthemeprovider"
13+
},
14+
"versions": [
15+
"99999.0.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "0ba7699d05c1cb95acd0b80e8a03bc6cb8eb0fa29339f261fe7d5d637ecd7550",
34+
"import_time": "2026-03-22T06:22:29.513153315Z",
35+
"modified_time": "2026-03-22T05:55:36Z",
36+
"versions": [
37+
"99999.0.0"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-22T06:07:52Z",
3+
"published": "2026-03-22T06:07:52Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @mesh-helpers/themehelper (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@mesh-helpers/themehelper' @ 99999.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@mesh-helpers/themehelper"
13+
},
14+
"versions": [
15+
"99999.0.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "4025b0ac5fa876e2c465db2fdd4fab6d93919502a53d1c0673411e3515cd3e72",
34+
"import_time": "2026-03-22T06:22:29.658491518Z",
35+
"modified_time": "2026-03-22T06:07:52Z",
36+
"versions": [
37+
"99999.0.0"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-22T06:15:56Z",
3+
"published": "2026-03-22T06:15:56Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in repo-typescript-config (npm)",
7+
"details": "The OpenSSF Package Analysis project identified 'repo-typescript-config' @ 99.0.11 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "repo-typescript-config"
13+
},
14+
"versions": [
15+
"99.0.11"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "7da27827fc7afc556d812f27d2840b817ba4f1ef06bb438c016a11be3496ab40",
34+
"import_time": "2026-03-22T06:22:29.72794713Z",
35+
"modified_time": "2026-03-22T06:15:56Z",
36+
"versions": [
37+
"99.0.11"
38+
]
39+
}
40+
]
41+
}
42+
}

0 commit comments

Comments
 (0)