Skip to content

Commit e7184d7

Browse files
author
github-actions
committed
Assign IDs
1 parent e63bda0 commit e7184d7

File tree

6 files changed

+32
-96
lines changed

6 files changed

+32
-96
lines changed

osv/malicious/.id-allocator

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
26a2261841e0673784f5b0fa1366d258b64ff1eff272ee2898badd21cb44a752
1+
2a112d2e60199691f667f14901cfaca8848561ca4562fcef231c2b0cad7f180f

osv/malicious/npm/nintendoamerica-ncom/MAL-0000-ossf-package-analysis-e77b311f9b7e9e93.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/nintendoamerica-ncom/MAL-2026-2008.json

Lines changed: 15 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,19 @@
11
{
2-
"modified": "2026-03-21T05:40:41Z",
2+
"modified": "2026-03-21T10:10:54Z",
33
"published": "2026-03-21T05:40:41Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2026-2008",
66
"summary": "Malicious code in nintendoamerica-ncom (npm)",
7-
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (7b638ac33d4412bfc3c7d3bc1d5f935f1966b743badfe353e134ff907d3e1b8f)\nThe OpenSSF Package Analysis project identified 'nintendoamerica-ncom' @ 1.0.5 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (e77b311f9b7e9e9303cab9b4b2a926d9dd50cbd5cc8196be52e888925f36bb89)\nThe OpenSSF Package Analysis project identified 'nintendoamerica-ncom' @ 99.0.7 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
88
"affected": [
99
{
1010
"package": {
1111
"ecosystem": "npm",
1212
"name": "nintendoamerica-ncom"
1313
},
1414
"versions": [
15-
"1.0.5"
15+
"1.0.5",
16+
"99.0.7"
1617
]
1718
}
1819
],
@@ -29,13 +30,22 @@
2930
"database_specific": {
3031
"malicious-packages-origins": [
3132
{
33+
"source": "ossf-package-analysis",
34+
"sha256": "7b638ac33d4412bfc3c7d3bc1d5f935f1966b743badfe353e134ff907d3e1b8f",
3235
"import_time": "2026-03-21T05:47:19.194998093Z",
3336
"modified_time": "2026-03-21T05:40:41Z",
34-
"sha256": "7b638ac33d4412bfc3c7d3bc1d5f935f1966b743badfe353e134ff907d3e1b8f",
35-
"source": "ossf-package-analysis",
3637
"versions": [
3738
"1.0.5"
3839
]
40+
},
41+
{
42+
"source": "ossf-package-analysis",
43+
"sha256": "e77b311f9b7e9e9303cab9b4b2a926d9dd50cbd5cc8196be52e888925f36bb89",
44+
"import_time": "2026-03-21T10:08:51.495852685Z",
45+
"modified_time": "2026-03-21T10:05:44Z",
46+
"versions": [
47+
"99.0.7"
48+
]
3949
}
4050
]
4151
}

osv/malicious/npm/uipathisfun/MAL-0000-ossf-package-analysis-f68ed829f1cbda04.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/uipathisfun/MAL-2026-1983.json

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
2-
"modified": "2026-03-21T09:46:11Z",
2+
"modified": "2026-03-21T10:10:56Z",
33
"published": "2026-03-20T07:05:46Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2026-1983",
@@ -23,7 +23,8 @@
2323
"1.0.14",
2424
"1.0.15",
2525
"1.0.16",
26-
"1.0.17"
26+
"1.0.17",
27+
"1.0.20"
2728
]
2829
}
2930
],
@@ -146,6 +147,15 @@
146147
"versions": [
147148
"1.0.17"
148149
]
150+
},
151+
{
152+
"source": "ossf-package-analysis",
153+
"sha256": "f68ed829f1cbda041340ebd648283ab5fd5ab2c539e09590a949b63f4550e0b4",
154+
"import_time": "2026-03-21T10:08:51.441195517Z",
155+
"modified_time": "2026-03-21T09:56:47Z",
156+
"versions": [
157+
"1.0.20"
158+
]
149159
}
150160
]
151161
}

osv/malicious/npm/yelp-react-component-badge/MAL-0000-ossf-package-analysis-8b6dade7daa9669a.json renamed to osv/malicious/npm/yelp-react-component-badge/MAL-2026-2010.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
"modified": "2026-03-21T09:50:35Z",
33
"published": "2026-03-21T09:50:35Z",
44
"schema_version": "1.7.4",
5-
"id": "",
5+
"id": "MAL-2026-2010",
66
"summary": "Malicious code in yelp-react-component-badge (npm)",
7-
"details": "The OpenSSF Package Analysis project identified 'yelp-react-component-badge' @ 99.0.4 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (8b6dade7daa9669ae0230e60fbdcca448ec07c3e0386b27e324be83e525cadca)\nThe OpenSSF Package Analysis project identified 'yelp-react-component-badge' @ 99.0.4 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
88
"affected": [
99
{
1010
"package": {
@@ -29,10 +29,10 @@
2929
"database_specific": {
3030
"malicious-packages-origins": [
3131
{
32-
"source": "ossf-package-analysis",
33-
"sha256": "8b6dade7daa9669ae0230e60fbdcca448ec07c3e0386b27e324be83e525cadca",
3432
"import_time": "2026-03-21T10:08:51.358143247Z",
3533
"modified_time": "2026-03-21T09:50:35Z",
34+
"sha256": "8b6dade7daa9669ae0230e60fbdcca448ec07c3e0386b27e324be83e525cadca",
35+
"source": "ossf-package-analysis",
3636
"versions": [
3737
"99.0.4"
3838
]

0 commit comments

Comments
 (0)