Skip to content

Commit efad9c3

Browse files
author
github-actions
committed
Ingest OSV - Cloud Storage
1 parent 38c5931 commit efad9c3

File tree

6 files changed

+225
-2
lines changed

6 files changed

+225
-2
lines changed

config/start-keys.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
amazon-inspector:
22
IN-MAL-: IN-MAL-2026-000461.json
33
kam193:
4-
pypi/packages/malicious/osv/: 22c5b6b33f222fe5bb87777473653b6bc4e66233
4+
pypi/packages/malicious/osv/: 7abc59ef1080f09c33e50ed19e56c059b6f4e6c7
55
pypi/packages/pentest/osv/: 0d65fa30569acb74a4cd2f6968297f9cf794b510
66
pypi/packages/probably_pentest/osv/: d85355ff7c5f46aa548621c0248747e10eee650a
77
ossf-package-analysis:
8-
confident/: confident/20260321/101817-npm-nintendoamerica-ncom-99.0.19.json
8+
confident/: confident/20260321/111943-npm-uipathisfun-1.0.24.json
99
reversing-labs:
1010
RLMA-: RLMA-2026-01666.json
1111
RLUA-: RLUA-2026-01611.json
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-21T22:57:53Z",
3+
"published": "2026-03-21T22:57:53Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @modals/blockchain (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@modals/blockchain' @ 99999.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@modals/blockchain"
13+
},
14+
"versions": [
15+
"99999.0.1"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "21323c6073b08f12b7cdd4f39bddd6eddde6bcde93041da8b41df45b79ae89e1",
34+
"import_time": "2026-03-21T23:09:18.378834745Z",
35+
"modified_time": "2026-03-21T22:57:53Z",
36+
"versions": [
37+
"99999.0.1"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-21T22:54:09Z",
3+
"published": "2026-03-21T22:54:09Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @modals/blockchain (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@modals/blockchain' @ 99999.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@modals/blockchain"
13+
},
14+
"versions": [
15+
"99999.0.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "22bfdc93e5d10d896a7e0dde6d162c209e246f0bfe3c550a0a5e1185b46eeb89",
34+
"import_time": "2026-03-21T23:09:18.315436975Z",
35+
"modified_time": "2026-03-21T22:54:09Z",
36+
"versions": [
37+
"99999.0.0"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-21T22:54:07Z",
3+
"published": "2026-03-21T22:54:07Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @modals/layout (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@modals/layout' @ 99999.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@modals/layout"
13+
},
14+
"versions": [
15+
"99999.0.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "423ea5070da3529e74e772e47cd0109f3dfc4a483645bfd0537e9007bd9ec60d",
34+
"import_time": "2026-03-21T23:09:18.220892275Z",
35+
"modified_time": "2026-03-21T22:54:07Z",
36+
"versions": [
37+
"99999.0.0"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2026-03-21T22:57:55Z",
3+
"published": "2026-03-21T22:57:55Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in @modals/layout (npm)",
7+
"details": "The OpenSSF Package Analysis project identified '@modals/layout' @ 99999.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "@modals/layout"
13+
},
14+
"versions": [
15+
"99999.0.1"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "96441eae186edd4ea411d23ed37960f469e9609f6ab9af1b6fd0d2ca3143d6c7",
34+
"import_time": "2026-03-21T23:09:18.449475805Z",
35+
"modified_time": "2026-03-21T22:57:55Z",
36+
"versions": [
37+
"99999.0.1"
38+
]
39+
}
40+
]
41+
}
42+
}
Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,55 @@
1+
{
2+
"modified": "2026-03-21T22:53:52Z",
3+
"published": "2026-03-21T22:53:52Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in aiolrucache (PyPI)",
7+
"details": "The package masquerades as a utility, but during import, code loads obfuscated modules with RAT- and spyware-like functionality, including: exfiltrating files, executing remote code, taking screenshots, monitoring and exfiltrating the clipboard content. Malicious code is controlled via Discord.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-03-aiolrucache\n\n\nReasons (based on the campaign):\n\n\n - rat\n\n\n - spyware-like\n\n\n - keylogger\n\n\n - clipboard-stealing\n\n\n - obfuscation\n\n\n - files-exfiltration\n\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "PyPI",
12+
"name": "aiolrucache"
13+
},
14+
"versions": [
15+
"0.1.0",
16+
"0.1.1",
17+
"0.2.0",
18+
"0.3.0"
19+
]
20+
}
21+
],
22+
"references": [
23+
{
24+
"type": "WEB",
25+
"url": "https://bad-packages.kam193.eu/pypi/package/aiolrucache"
26+
}
27+
],
28+
"credits": [
29+
{
30+
"name": "Kamil Mańkowski (kam193)",
31+
"type": "REPORTER",
32+
"contact": [
33+
"https://github.com/kam193",
34+
"https://bad-packages.kam193.eu/"
35+
]
36+
}
37+
],
38+
"database_specific": {
39+
"malicious-packages-origins": [
40+
{
41+
"source": "kam193",
42+
"sha256": "8b847ab6789b3a3848d887f76adae74d05523dd4cb1a974372518679d27ed70e",
43+
"import_time": "2026-03-21T23:09:36.572115179Z",
44+
"id": "pypi/2026-03-aiolrucache/aiolrucache",
45+
"modified_time": "2026-03-21T22:53:52.472149Z",
46+
"versions": [
47+
"0.1.0",
48+
"0.1.1",
49+
"0.2.0",
50+
"0.3.0"
51+
]
52+
}
53+
]
54+
}
55+
}

0 commit comments

Comments
 (0)