Skip to content

Commit ba487cd

Browse files
author
github-actions
committed
Assign IDs
1 parent c072260 commit ba487cd

14 files changed

+93
-317
lines changed

osv/malicious/.id-allocator

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
ab88da95da4607b91a0300f7dda129a4329b6cb89950ec3f1608ba2e1f1f9628
1+
a10973d674b25ef28fc98b61e6042fb18d9194bb4dadc7009c6bb0fe8dbf204d
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
"modified": "2025-11-27T23:25:43Z",
33
"published": "2025-11-27T23:25:43Z",
44
"schema_version": "1.7.4",
5-
"id": "",
5+
"id": "MAL-2025-191480",
66
"summary": "Malicious code in accounts-base (npm)",
7-
"details": "The OpenSSF Package Analysis project identified 'accounts-base' @ 23.5.6 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (91aded18014deeb9f278bcd61adcdf917bad7b7e50159b48c125f453f19681cf)\nThe OpenSSF Package Analysis project identified 'accounts-base' @ 23.5.6 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
88
"affected": [
99
{
1010
"package": {
@@ -29,10 +29,10 @@
2929
"database_specific": {
3030
"malicious-packages-origins": [
3131
{
32-
"source": "ossf-package-analysis",
33-
"sha256": "91aded18014deeb9f278bcd61adcdf917bad7b7e50159b48c125f453f19681cf",
3432
"import_time": "2025-11-28T04:40:13.367968919Z",
3533
"modified_time": "2025-11-27T23:25:43Z",
34+
"sha256": "91aded18014deeb9f278bcd61adcdf917bad7b7e50159b48c125f453f19681cf",
35+
"source": "ossf-package-analysis",
3636
"versions": [
3737
"23.5.6"
3838
]

osv/malicious/npm/bitcoin-main-lib/MAL-0000-ossf-package-analysis-054a38c3f0ef13d7.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/bitcoin-main-lib/MAL-0000-ossf-package-analysis-0bedb99d5abf7b3e.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/bitcoin-main-lib/MAL-0000-ossf-package-analysis-73907f05ac4fa2d2.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/bitcoin-main-lib/MAL-0000-ossf-package-analysis-b5dfcb3d7ee3ceba.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/bitcoin-main-lib/MAL-0000-ossf-package-analysis-bd46e3f440615dbe.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/bitcoin-main-lib/MAL-0000-ossf-package-analysis-e897ed7e870743b4.json

Lines changed: 0 additions & 42 deletions
This file was deleted.

osv/malicious/npm/bitcoin-main-lib/MAL-2025-191477.json

Lines changed: 63 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
2-
"modified": "2025-11-27T07:25:14Z",
3-
"published": "2025-11-26T12:35:56Z",
2+
"modified": "2025-11-28T04:42:03Z",
3+
"published": "2025-11-26T10:15:45Z",
44
"schema_version": "1.7.4",
55
"id": "MAL-2025-191477",
66
"aliases": [
@@ -25,7 +25,13 @@
2525
}
2626
],
2727
"versions": [
28-
"7.1.6"
28+
"7.1.6",
29+
"7.1.7",
30+
"7.1.8",
31+
"7.1.1",
32+
"7.1.4",
33+
"7.1.2",
34+
"7.1.0"
2935
],
3036
"database_specific": {
3137
"cwes": [
@@ -81,6 +87,60 @@
8187
]
8288
}
8389
]
90+
},
91+
{
92+
"source": "ossf-package-analysis",
93+
"sha256": "054a38c3f0ef13d700fd10fae31053babcfe33fa983b170d4bafca9b44164482",
94+
"import_time": "2025-11-28T04:40:12.916686092Z",
95+
"modified_time": "2025-11-26T12:40:43Z",
96+
"versions": [
97+
"7.1.7"
98+
]
99+
},
100+
{
101+
"source": "ossf-package-analysis",
102+
"sha256": "0bedb99d5abf7b3e4e2dedba092a3124f7858b3153fbb135b2b85c49343d0917",
103+
"import_time": "2025-11-28T04:40:13.04630766Z",
104+
"modified_time": "2025-11-26T12:45:51Z",
105+
"versions": [
106+
"7.1.8"
107+
]
108+
},
109+
{
110+
"source": "ossf-package-analysis",
111+
"sha256": "73907f05ac4fa2d28e5e012a5a05f9d502a96a44dda66872764c75208190bf8e",
112+
"import_time": "2025-11-28T04:40:12.61736516Z",
113+
"modified_time": "2025-11-26T11:00:41Z",
114+
"versions": [
115+
"7.1.1"
116+
]
117+
},
118+
{
119+
"source": "ossf-package-analysis",
120+
"sha256": "b5dfcb3d7ee3ceba7d33dc7da0e380f84c69eaf12a7c31ed001038742e8bec4b",
121+
"import_time": "2025-11-28T04:40:12.822453083Z",
122+
"modified_time": "2025-11-26T12:16:18Z",
123+
"versions": [
124+
"7.1.4"
125+
]
126+
},
127+
{
128+
"source": "ossf-package-analysis",
129+
"sha256": "bd46e3f440615dbe75731ac06ed22f0f1b36513dc228181c6c8a61f8352157fa",
130+
"import_time": "2025-11-28T04:40:12.715303421Z",
131+
"modified_time": "2025-11-26T11:11:26Z",
132+
"versions": [
133+
"7.1.2"
134+
]
135+
},
136+
{
137+
"source": "ossf-package-analysis",
138+
"sha256": "e897ed7e870743b446ea45a6dba531c1bc438069a626f6f5848c9a00cbc996af",
139+
"import_time": "2025-11-28T04:40:12.491165284Z",
140+
"modified_time": "2025-11-26T10:15:45Z",
141+
"versions": [
142+
"7.1.0"
143+
]
84144
}
85145
]
86146
}
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
"modified": "2025-11-26T08:44:02Z",
33
"published": "2025-11-26T08:44:02Z",
44
"schema_version": "1.7.4",
5-
"id": "",
5+
"id": "MAL-2025-191481",
66
"summary": "Malicious code in br2s-ui-componentlibrary_r2 (npm)",
7-
"details": "The OpenSSF Package Analysis project identified 'br2s-ui-componentlibrary_r2' @ 2.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
7+
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ossf-package-analysis (d6f54e2f7fa6e6ef49cf10c2c5cc36fd45a39ccae9a7216ba5cc215ca70e78da)\nThe OpenSSF Package Analysis project identified 'br2s-ui-componentlibrary_r2' @ 2.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n",
88
"affected": [
99
{
1010
"package": {
@@ -29,10 +29,10 @@
2929
"database_specific": {
3030
"malicious-packages-origins": [
3131
{
32-
"source": "ossf-package-analysis",
33-
"sha256": "d6f54e2f7fa6e6ef49cf10c2c5cc36fd45a39ccae9a7216ba5cc215ca70e78da",
3432
"import_time": "2025-11-28T04:40:12.364705645Z",
3533
"modified_time": "2025-11-26T08:44:02Z",
34+
"sha256": "d6f54e2f7fa6e6ef49cf10c2c5cc36fd45a39ccae9a7216ba5cc215ca70e78da",
35+
"source": "ossf-package-analysis",
3636
"versions": [
3737
"2.0.0"
3838
]

0 commit comments

Comments
 (0)