From de4688e84ec8ffdcbd13afb836c0cf3210e94492 Mon Sep 17 00:00:00 2001 From: github-actions Date: Tue, 3 Dec 2024 02:03:25 +0000 Subject: [PATCH] Assign IDs --- osv/malicious/.id-allocator | 2 +- ...31f663782c2e1.json => MAL-2024-10397.json} | 21 +++++++++---------- 2 files changed, 11 insertions(+), 12 deletions(-) rename osv/malicious/npm/synch-prod-ai/{MAL-0000-ghsa-malware-ff531f663782c2e1.json => MAL-2024-10397.json} (63%) diff --git a/osv/malicious/.id-allocator b/osv/malicious/.id-allocator index 7ab71647672..a5a5aa72c99 100644 --- a/osv/malicious/.id-allocator +++ b/osv/malicious/.id-allocator @@ -1 +1 @@ -d8c0ff674e136587e7b102be2bd16a1b5dd88fb1dc6d9f496a29a220e88fdc96 \ No newline at end of file +d2b229035eddd4e6c89989bd140aacd2544147ea00fba5238c94524418b76d74 \ No newline at end of file diff --git a/osv/malicious/npm/synch-prod-ai/MAL-0000-ghsa-malware-ff531f663782c2e1.json b/osv/malicious/npm/synch-prod-ai/MAL-2024-10397.json similarity index 63% rename from osv/malicious/npm/synch-prod-ai/MAL-0000-ghsa-malware-ff531f663782c2e1.json rename to osv/malicious/npm/synch-prod-ai/MAL-2024-10397.json index 43e621c6478..78befbdafe3 100644 --- a/osv/malicious/npm/synch-prod-ai/MAL-0000-ghsa-malware-ff531f663782c2e1.json +++ b/osv/malicious/npm/synch-prod-ai/MAL-2024-10397.json @@ -2,12 +2,12 @@ "modified": "2024-12-02T05:33:28Z", "published": "2024-12-02T05:33:28Z", "schema_version": "1.5.0", - "id": "", + "id": "MAL-2024-10397", "aliases": [ "GHSA-82rx-43q9-hqxr" ], - "summary": "Malware in synch-prod-ai", - "details": "Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.", + "summary": "Malicious code in synch-prod-ai (npm)", + "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: ghsa-malware (ff531f663782c2e1a1b12202fa492a99336662a683528d75910f308b12a22dbf)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n", "affected": [ { "package": { @@ -31,8 +31,7 @@ "description": "The product contains code that appears to be malicious in nature.", "name": "Embedded Malicious Code" } - ], - "ghsa": "https://github.com/advisories/GHSA-82rx-43q9-hqxr" + ] } } ], @@ -45,21 +44,21 @@ "database_specific": { "malicious-packages-origins": [ { - "source": "ghsa-malware", - "sha256": "ff531f663782c2e1a1b12202fa492a99336662a683528d75910f308b12a22dbf", - "import_time": "2024-12-03T02:02:41.282427456Z", "id": "GHSA-82rx-43q9-hqxr", + "import_time": "2024-12-03T02:02:41.282427456Z", "modified_time": "2024-12-02T05:33:28Z", "ranges": [ { - "type": "SEMVER", "events": [ { "introduced": "0" } - ] + ], + "type": "SEMVER" } - ] + ], + "sha256": "ff531f663782c2e1a1b12202fa492a99336662a683528d75910f308b12a22dbf", + "source": "ghsa-malware" } ] }