Skip to content

Commit 13b6175

Browse files
author
github-actions
committed
Assign IDs
1 parent 142e7a2 commit 13b6175

File tree

3 files changed

+17
-49
lines changed

3 files changed

+17
-49
lines changed

osv/malicious/.id-allocator

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
90b1ed6268f94a2debd8e6d464e82eb51a789008d68c2e480de65f0bbd3428ed
1+
313960b575ff12cf4885146a36da94a960591d3555944381f19cf281dd141ba5

osv/malicious/npm/gs-uitk-lodash/MAL-0000-ossf-package-analysis-feecd7d802ec1993.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/gs-uitk-lodash/MAL-0000-ossf-package-analysis-c89a6d85d1019b9d.json renamed to osv/malicious/npm/gs-uitk-lodash/MAL-2025-192377.json

Lines changed: 16 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,19 @@
11
{
2-
"modified": "2025-12-08T15:40:53Z",
2+
"modified": "2025-12-08T16:10:15Z",
33
"published": "2025-12-08T15:40:53Z",
44
"schema_version": "1.7.4",
5-
"id": "",
5+
"id": "MAL-2025-192377",
66
"summary": "Malicious code in gs-uitk-lodash (npm)",
7-
"details": "The OpenSSF Package Analysis project identified 'gs-uitk-lodash' @ 35.3.3 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd)\nThe OpenSSF Package Analysis project identified 'gs-uitk-lodash' @ 35.3.3 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
88
"affected": [
99
{
1010
"package": {
1111
"ecosystem": "npm",
1212
"name": "gs-uitk-lodash"
1313
},
1414
"versions": [
15-
"35.3.3"
15+
"35.3.3",
16+
"35.9.9"
1617
]
1718
}
1819
],
@@ -29,13 +30,22 @@
2930
"database_specific": {
3031
"malicious-packages-origins": [
3132
{
32-
"source": "ossf-package-analysis",
33-
"sha256": "c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd",
3433
"import_time": "2025-12-08T16:08:29.958933342Z",
3534
"modified_time": "2025-12-08T15:40:53Z",
35+
"sha256": "c89a6d85d1019b9d98f88e94d18fd4ec4ae045bd6f941941e9bdde517a749fdd",
36+
"source": "ossf-package-analysis",
3637
"versions": [
3738
"35.3.3"
3839
]
40+
},
41+
{
42+
"import_time": "2025-12-08T16:08:30.077469565Z",
43+
"modified_time": "2025-12-08T16:06:53Z",
44+
"sha256": "feecd7d802ec19931f6a91819521c5409d84adc3ee12e026f16c3f2df1384d9c",
45+
"source": "ossf-package-analysis",
46+
"versions": [
47+
"35.9.9"
48+
]
3949
}
4050
]
4151
}

0 commit comments

Comments
 (0)