-
Notifications
You must be signed in to change notification settings - Fork 66
Description
We previously reported these three npm packages and their multiple versions as malicious:
pap-sdk: MAL-2024-11062rollup-plugin-hotreload: MAL-2024-11081soybean-admin-tab: MAL-2024-11098
When doing our own research it was concluded that not all reported versions are actually malicious. We would like to update the status on the OSSF repo in accordance with the false positive guide, constitute with removing the non-malicious versions
.
However, the packages in question were removed from npm registry, and it seems it was either hijacked or a malicious actor got hold of it and published a few malicious versions. We'd like to make sure we're on the same page with keeping only the strictly malicious versions in the OSSF advisory, as opposed to leaving them all in.
In this instance we are also not the only reporters, so we may not be able to remove anything at all since it would contradict the GHSA advisory?
Can you please advise us how to proceed?