Skip to content

Commit

Permalink
Assign IDs
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed May 20, 2024
1 parent 702c6ee commit c13e463
Show file tree
Hide file tree
Showing 4 changed files with 31 additions and 34 deletions.
2 changes: 1 addition & 1 deletion osv/malicious/.id-allocator
Original file line number Diff line number Diff line change
@@ -1 +1 @@
fabcae8136397c67975cd23c7a687898a2780df9eba2aeb8d04ea8dab7e0426c
21a51907da40b722727f4af69c05385ba06b3a09ab62a61125ccc0f8ad393201
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,12 @@
"modified": "2024-05-19T23:47:46Z",
"published": "2024-05-19T23:47:45Z",
"schema_version": "1.5.0",
"id": "",
"id": "MAL-2024-1367",
"aliases": [
"GHSA-rm75-mp2m-cj3v"
],
"summary": "Malware in brand-adidas-asset-fonts",
"details": "Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"summary": "Malicious code in brand-adidas-asset-fonts (npm)",
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (35b2e8dbb891acdef0e8c7d2e97c0b27c3e6e9d4fb4ff284fa0d9542acb2c893)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n",
"affected": [
{
"package": {
Expand All @@ -31,8 +31,7 @@
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"ghsa": "https://github.com/advisories/GHSA-rm75-mp2m-cj3v"
]
}
}
],
Expand All @@ -45,21 +44,21 @@
"database_specific": {
"malicious-packages-origins": [
{
"source": "ghsa-malware",
"sha256": "35b2e8dbb891acdef0e8c7d2e97c0b27c3e6e9d4fb4ff284fa0d9542acb2c893",
"import_time": "2024-05-20T00:26:17.597042771Z",
"id": "GHSA-rm75-mp2m-cj3v",
"import_time": "2024-05-20T00:26:17.597042771Z",
"modified_time": "2024-05-19T23:47:46Z",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
],
"type": "SEMVER"
}
]
],
"sha256": "35b2e8dbb891acdef0e8c7d2e97c0b27c3e6e9d4fb4ff284fa0d9542acb2c893",
"source": "ghsa-malware"
}
]
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,12 @@
"modified": "2024-05-19T23:47:46Z",
"published": "2024-05-19T23:47:45Z",
"schema_version": "1.5.0",
"id": "",
"id": "MAL-2024-1368",
"aliases": [
"GHSA-9pmf-m6cj-8frm"
],
"summary": "Malware in brand-adidas-design-tokens",
"details": "Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"summary": "Malicious code in brand-adidas-design-tokens (npm)",
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (7e16fae72fd3726263d7bfa2f1c164b7d4100f89931856c163e37c534feb1a57)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n",
"affected": [
{
"package": {
Expand All @@ -31,8 +31,7 @@
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"ghsa": "https://github.com/advisories/GHSA-9pmf-m6cj-8frm"
]
}
}
],
Expand All @@ -45,21 +44,21 @@
"database_specific": {
"malicious-packages-origins": [
{
"source": "ghsa-malware",
"sha256": "7e16fae72fd3726263d7bfa2f1c164b7d4100f89931856c163e37c534feb1a57",
"import_time": "2024-05-20T00:26:17.595885915Z",
"id": "GHSA-9pmf-m6cj-8frm",
"import_time": "2024-05-20T00:26:17.595885915Z",
"modified_time": "2024-05-19T23:47:46Z",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
],
"type": "SEMVER"
}
]
],
"sha256": "7e16fae72fd3726263d7bfa2f1c164b7d4100f89931856c163e37c534feb1a57",
"source": "ghsa-malware"
}
]
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,12 @@
"modified": "2024-05-19T23:57:16Z",
"published": "2024-05-19T23:57:16Z",
"schema_version": "1.5.0",
"id": "",
"id": "MAL-2024-1369",
"aliases": [
"GHSA-5p24-mg88-p6hj"
],
"summary": "Malware in mixtral-llm",
"details": "Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"summary": "Malicious code in mixtral-llm (npm)",
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (d8f29dbee4aa92684c9adc9e0484e255cac83931500c1651073b71123d728fd8)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n",
"affected": [
{
"package": {
Expand All @@ -31,8 +31,7 @@
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"ghsa": "https://github.com/advisories/GHSA-5p24-mg88-p6hj"
]
}
}
],
Expand All @@ -45,21 +44,21 @@
"database_specific": {
"malicious-packages-origins": [
{
"source": "ghsa-malware",
"sha256": "d8f29dbee4aa92684c9adc9e0484e255cac83931500c1651073b71123d728fd8",
"import_time": "2024-05-20T00:26:17.590285964Z",
"id": "GHSA-5p24-mg88-p6hj",
"import_time": "2024-05-20T00:26:17.590285964Z",
"modified_time": "2024-05-19T23:57:16Z",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
],
"type": "SEMVER"
}
]
],
"sha256": "d8f29dbee4aa92684c9adc9e0484e255cac83931500c1651073b71123d728fd8",
"source": "ghsa-malware"
}
]
}
Expand Down

0 comments on commit c13e463

Please sign in to comment.