Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
45 commits
Select commit Hold shift + click to select a range
f74e371
Add malicious package entry: ab-test-wordpress
awsactran Oct 14, 2025
56730bf
Add malicious package entry: ab-testing-for-wp
awsactran Oct 14, 2025
82f08c9
Add malicious package entry: spot-electron-sdk
awsactran Oct 14, 2025
d4e2d38
Add malicious package entry: debug-mj-v3
awsactran Oct 14, 2025
cd6351b
Add malicious package entry: debug-mj
awsactran Oct 14, 2025
13ff0d4
Add malicious package entry: sb_wm_integrator
awsactran Oct 14, 2025
f23f44c
Add malicious package entry: iwf-ant-design-draggable-modal
awsactran Oct 14, 2025
d89ad89
Add malicious package entry: private-callout-queue
awsactran Oct 14, 2025
66ab1b8
Add malicious package entry: private-callouts
awsactran Oct 14, 2025
cd22dce
Add malicious package entry: company-request-access
awsactran Oct 14, 2025
eebede1
Add malicious package entry: company-overview
awsactran Oct 14, 2025
d3b7b1d
Add malicious package entry: company-access-pending
awsactran Oct 14, 2025
550ddeb
Add malicious package entry: company-logo
awsactran Oct 14, 2025
f0935a0
Added reports
awsactran Oct 14, 2025
234a6db
Added & merged reports
awsactran Oct 14, 2025
6d57695
Merge branch 'main' into add-malicious-packages
awsactran Oct 14, 2025
38752a9
Added reports
awsactran Oct 14, 2025
cde526e
Added reports
awsactran Oct 14, 2025
95f167e
Add malicious package entry: tombac
awsactran Oct 14, 2025
0bd6d35
Add malicious package entry: arno-baidu-test
awsactran Oct 14, 2025
cd56424
Add malicious package entry: package-g
awsactran Oct 14, 2025
a980842
Add malicious package entry: batchw-test-common-config
awsactran Oct 14, 2025
3ba70e6
Merge branch 'main' into add-malicious-packages
awsactran Oct 14, 2025
1353440
Merged report
awsactran Oct 14, 2025
f1d4d6b
Merge branch 'main' into add-malicious-packages
awsactran Oct 15, 2025
a533aba
Added reports
awsactran Oct 15, 2025
f287584
Add malicious package entry: package-f
awsactran Oct 15, 2025
1db4f7a
Added reports
awsactran Oct 15, 2025
eed3c4d
Merge branch 'main' into add-malicious-packages
awsactran Oct 15, 2025
37ab830
Merge branch 'main' into add-malicious-packages
awsactran Oct 15, 2025
ea267ce
Merge branch 'main' into add-malicious-packages
awsactran Oct 17, 2025
8dbc410
Added reports
awsactran Oct 17, 2025
a3a85a7
Add malicious package entry: internal-forc
awsactran Oct 17, 2025
3aec100
Add malicious package entry: internal-config
awsactran Oct 17, 2025
f7e9b08
Add malicious package entry: api_halodoc
awsactran Oct 17, 2025
d668496
Add malicious package entry: @nunes_nunes/loader-base
awsactran Oct 17, 2025
b1832f7
Add malicious package entry: ec-component-loader
awsactran Oct 17, 2025
211a860
Added reports
awsactran Oct 17, 2025
61dd1ca
Merge branch 'main' into add-malicious-packages
awsactran Oct 17, 2025
559ae04
Merged reports
awsactran Oct 17, 2025
df90dfa
Merge branch 'main' into add-malicious-packages
awsactran Oct 17, 2025
69b1b7b
Add malicious package entry: class-scheduling
awsactran Oct 17, 2025
50f5d2d
Add malicious package entry: @institute-of-data-management/n11-chatbot
awsactran Oct 17, 2025
e23df51
Add malicious package entry: internal-native-buy
awsactran Oct 17, 2025
c9869ab
Added reports
awsactran Oct 17, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @custom-widget/sdk (npm)",
"details": "The package @custom-widget/sdk was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@custom-widget/sdk"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,15 @@
}
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"references": [
{
"type": "ADVISORY",
Expand Down Expand Up @@ -62,4 +71,4 @@
}
]
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @gala-analytics/core (npm)",
"details": "The package @gala-analytics/core was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@gala-analytics/core"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @gtpn/eslint-config-progressive (npm)",
"details": "The package @gtpn/eslint-config-progressive was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@gtpn/eslint-config-progressive"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @hotels-at-home/hah-fe-core (npm)",
"details": "The package @hotels-at-home/hah-fe-core was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@hotels-at-home/hah-fe-core"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T15:45:22Z",
"published": "2025-10-17T15:45:22Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @institute-of-data-management/n11-chatbot (npm)",
"details": "The package communicates with a domain associated with malicious activity.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@institute-of-data-management/n11-chatbot"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "1.0.0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @naviance/translation-client (npm)",
"details": "The package @naviance/translation-client was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@naviance/translation-client"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:26:41Z",
"published": "2025-10-17T03:26:41Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @nunes_nunes/loader-base (npm)",
"details": "The package communicates with a domain associated with malicious activity.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@nunes_nunes/loader-base"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0.1.0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @sudt-faucet/commons (npm)",
"details": "The package @sudt-faucet/commons was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@sudt-faucet/commons"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"modified": "2025-10-17T03:28:23Z",
"published": "2025-10-17T03:28:23Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in @taskrabbit/meadow-web (npm)",
"details": "The package @taskrabbit/meadow-web was found to contain malicious code.",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@taskrabbit/meadow-web"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"credits": [
{
"name": "Amazon Inspector",
"type": "FINDER",
"contact": [
"[email protected]"
]
}
],
"database_specific": {
"malicious-packages-origins": null
}
}
Loading
Loading