diff --git a/config/start-keys.yaml b/config/start-keys.yaml index 4fdbba0ec..5e63d9ffb 100644 --- a/config/start-keys.yaml +++ b/config/start-keys.yaml @@ -1,5 +1,5 @@ ossf-package-analysis: - confident/: confident/20241221/044544-npm-lerna-monorepo2-9.9.10.json + confident/: confident/20241221/070319-npm-@shahwarhello/l2geth-0.5.11.json reversing-labs: RLMA-: RLMA-2024-11212.json RLUA-: RLUA-2024-11114.json diff --git a/osv/malicious/npm/goji-js-org/MAL-0000-ossf-package-analysis-3a86bc73706871d1.json b/osv/malicious/npm/goji-js-org/MAL-0000-ossf-package-analysis-3a86bc73706871d1.json new file mode 100644 index 000000000..89c347528 --- /dev/null +++ b/osv/malicious/npm/goji-js-org/MAL-0000-ossf-package-analysis-3a86bc73706871d1.json @@ -0,0 +1,42 @@ +{ + "modified": "2024-12-21T20:15:59Z", + "published": "2024-12-21T20:15:59Z", + "schema_version": "1.5.0", + "id": "", + "summary": "Malicious code in goji-js-org (npm)", + "details": "The OpenSSF Package Analysis project identified 'goji-js-org' @ 2.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n", + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "goji-js-org" + }, + "versions": [ + "2.0.0" + ] + } + ], + "credits": [ + { + "name": "OpenSSF: Package Analysis", + "type": "FINDER", + "contact": [ + "https://github.com/ossf/package-analysis", + "https://openssf.slack.com/channels/package_analysis" + ] + } + ], + "database_specific": { + "malicious-packages-origins": [ + { + "source": "ossf-package-analysis", + "sha256": "3a86bc73706871d1dd1a48c538e2f5b87b952d0f06b4745dcef4dc0a18f2a010", + "import_time": "2024-12-21T20:34:07.774935991Z", + "modified_time": "2024-12-21T20:15:59Z", + "versions": [ + "2.0.0" + ] + } + ] + } +}