Skip to content

Commit cdd9bde

Browse files
author
github-actions
committed
Ingest OSV - Cloud Storage
1 parent ddc6f4c commit cdd9bde

File tree

2 files changed

+43
-1
lines changed

2 files changed

+43
-1
lines changed

config/start-keys.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
amazon-inspector:
22
IN-MAL-: IN-MAL-2025-148218.json
33
ossf-package-analysis:
4-
confident/: confident/20251128/152912-npm-br2s-ui-componentlibrary_r2-2.0.0.json
4+
confident/: confident/20251128/152914-npm-bitcoin-main-lib-7.1.0.json
55
reversing-labs:
66
RLMA-: RLMA-2025-05558.json
77
RLUA-: RLUA-2025-05510.json
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"modified": "2025-11-28T19:55:33Z",
3+
"published": "2025-11-28T19:55:33Z",
4+
"schema_version": "1.7.4",
5+
"id": "",
6+
"summary": "Malicious code in browser-client-neptune (npm)",
7+
"details": "The OpenSSF Package Analysis project identified 'browser-client-neptune' @ 99.99.91 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "browser-client-neptune"
13+
},
14+
"versions": [
15+
"99.99.91"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "OpenSSF: Package Analysis",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://github.com/ossf/package-analysis",
25+
"https://openssf.slack.com/channels/package_analysis"
26+
]
27+
}
28+
],
29+
"database_specific": {
30+
"malicious-packages-origins": [
31+
{
32+
"source": "ossf-package-analysis",
33+
"sha256": "5b96b5ccfba68767c612c54af1007c61dcc8f73615000650cfb480ceffab949e",
34+
"import_time": "2025-11-28T20:07:07.668191466Z",
35+
"modified_time": "2025-11-28T19:55:33Z",
36+
"versions": [
37+
"99.99.91"
38+
]
39+
}
40+
]
41+
}
42+
}

0 commit comments

Comments
 (0)