Skip to content

Commit b66d814

Browse files
author
github-actions
committed
Assign IDs
1 parent 2904327 commit b66d814

11 files changed

+156
-136
lines changed

osv/malicious/.id-allocator

+1-1
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
8beffa778dc81bdd5f4dd74f6fd73499abdcbdb4bb439b59fa3afa3fd14942ce
1+
8a1aeec49c0d94e52601c0d02d623712afaeb2a6528a9e0cc571b291ff06542f

osv/malicious/npm/archon1/MAL-0000-archon1.json

-27
This file was deleted.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"modified": "2025-02-23T05:01:18Z",
3+
"published": "2025-02-23T05:01:18Z",
4+
"schema_version": "1.5.0",
5+
"id": "MAL-2025-1535",
6+
"summary": "Malicious code in archon1 (npm)",
7+
"details": "This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "archon1"
13+
},
14+
"versions": [
15+
"1.1.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "GitHax - Software Supply Chain Threat Intelligence",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://githax.com"
25+
]
26+
}
27+
],
28+
"database_specific": {
29+
"malicious-packages-origins": null
30+
}
31+
}

osv/malicious/npm/archon4/MAL-0000-archon4.json

-27
This file was deleted.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"modified": "2025-02-23T05:01:18Z",
3+
"published": "2025-02-23T05:01:18Z",
4+
"schema_version": "1.5.0",
5+
"id": "MAL-2025-1536",
6+
"summary": "Malicious code in archon4 (npm)",
7+
"details": "This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "archon4"
13+
},
14+
"versions": [
15+
"1.1.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "GitHax - Software Supply Chain Threat Intelligence",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://githax.com"
25+
]
26+
}
27+
],
28+
"database_specific": {
29+
"malicious-packages-origins": null
30+
}
31+
}

osv/malicious/npm/archon6/MAL-0000-archon6.json

-27
This file was deleted.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"modified": "2025-02-23T05:01:18Z",
3+
"published": "2025-02-23T05:01:18Z",
4+
"schema_version": "1.5.0",
5+
"id": "MAL-2025-1537",
6+
"summary": "Malicious code in archon6 (npm)",
7+
"details": "This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "archon6"
13+
},
14+
"versions": [
15+
"1.2.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "GitHax - Software Supply Chain Threat Intelligence",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://githax.com"
25+
]
26+
}
27+
],
28+
"database_specific": {
29+
"malicious-packages-origins": null
30+
}
31+
}

osv/malicious/npm/dracoon/MAL-0000-dracoon.json

-27
This file was deleted.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"modified": "2025-02-23T05:01:18Z",
3+
"published": "2025-02-23T05:01:18Z",
4+
"schema_version": "1.5.0",
5+
"id": "MAL-2025-1538",
6+
"summary": "Malicious code in dracoon (npm)",
7+
"details": "This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "dracoon"
13+
},
14+
"versions": [
15+
"1.12.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "GitHax - Software Supply Chain Threat Intelligence",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://githax.com"
25+
]
26+
}
27+
],
28+
"database_specific": {
29+
"malicious-packages-origins": null
30+
}
31+
}

osv/malicious/npm/my-archon/MAL-0000-my-archon.json

-27
This file was deleted.
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"modified": "2025-02-23T05:01:18Z",
3+
"published": "2025-02-23T05:01:18Z",
4+
"schema_version": "1.5.0",
5+
"id": "MAL-2025-1539",
6+
"summary": "Malicious code in my-archon (npm)",
7+
"details": "This package runs commands in a pre-install script that exfils sensitive data to a attacker-controlled domain.",
8+
"affected": [
9+
{
10+
"package": {
11+
"ecosystem": "npm",
12+
"name": "my-archon"
13+
},
14+
"versions": [
15+
"1.1.0"
16+
]
17+
}
18+
],
19+
"credits": [
20+
{
21+
"name": "GitHax - Software Supply Chain Threat Intelligence",
22+
"type": "FINDER",
23+
"contact": [
24+
"https://githax.com"
25+
]
26+
}
27+
],
28+
"database_specific": {
29+
"malicious-packages-origins": null
30+
}
31+
}

0 commit comments

Comments
 (0)