GHSA-vxq2-vhm7-7mhq: expand fetch-page-assets affected versions beyond = 1.2.9
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- node.js
- Domain
- security
Research direction
Start by reviewing the linked GHSA and the existing fetch-page-assets advisory entry, then verify the npm versions and the public malware evidence cited in the issue. Update the affected-version data to include 1.2.10 through 1.2.14, and confirm that all five malicious versions are represented when the advisory is complete.
Written by the indexing model from the issue text.
Description
Advisory
https://github.com/advisories/GHSA-vxq2-vhm7-7mhq
Currently pinned to fetch-page-assets = 1.2.9.
Requested change
Add these still-malicious versions:
1.2.101.2.111.2.121.2.131.2.14
1.2.13 and 1.2.14 are already in MAL-2026-6358 (Amazon Inspector, 2026-08-25). 1.2.10–1.2.12 remain listed on the npm registry and were omitted from both this GHSA and the later Inspector additions.
Public sources
- OpenSourceMalware case study (tarball-verified
.vscode/tasks.jsonauto-run on 1.2.10/1.2.11; 1.2.12 restored the fake-font payload plus a NullReceiver loader inbabel.config.cjs): https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack - OSV update PR for MAL-2026-6358: https://github.com/ossf/malicious-packages/pull/1476
- npm packument still includes
1.2.10,1.2.11,1.2.12(as of 2026-08-28)
These GHSA malware records do not appear in this git tree, so this is an issue rather than an advisory-file PR.
- Dominant language
- No language data
- Stars
- 2.5k
- Forks
- 772
- Avg merge
- 3d 20h
- Merged PRs (30d)
- 49
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/advisory-database
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#9164 · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8994 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/advisory-database#8898 · 4 comments · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/advisory-database#8841 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
github/advisory-database#7882 · 1 comment ·
All issues in github/advisory-database
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
AXERA-TECH/ax-llm#75 ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
gitbutlerapp/gitbutler#15998 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
sympozium-ai/sympozium#627 ·
-
clawsweeper:needs-product-decision clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:security impact:ux-friction issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
TheManticoreProject/Manticore#1383 ·