False Positive Malware Flag on @znan/wabot (GHSA-2jxx-8fv2-h8mj)
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- javascript
- Lĩnh vực
- security
Hướng nghiên cứu
Bắt đầu bằng việc xem xét mã nguồn không bị làm rối trong repository znanx/wabot và so sánh với package @znan/wabot đã được phát hành, liên kết với GHSA-2jxx-8fv2-h8mj. Xác nhận liệu cờ malware có phải là false positive do quá trình làm rối bằng JSConfuser gây ra hay không; để hoàn tất, GitHub Security Team cần xem xét và gỡ bỏ hoặc sửa cờ advisory.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
False Positive Malware Flag on @znan/wabot (GHSA-2jxx-8fv2-h8mj)
Hello GitHub Security Team,
I am the author and maintainer of the npm package @znan/wabot and the repository znanx/wabot. My package was recently flagged as malware under GHSA-2jxx-8fv2-h8mj.
I would like to clarify that this is a false positive caused by code obfuscation, not malicious functionality. I use a tool called js-confuser to obfuscate the JavaScript output before publishing.
To be precise about my repo/publish setup: the original source code lives in a private repository. When I push changes there and create a release tag, the pipeline automatically builds the project, obfuscates the JS output with js-confuser, mirrors that obfuscated build to this public repository (znanx/wabot), and publishes the same obfuscated build to npm as @znan/wabot. So this public repo and the npm package contain the same obfuscated code, not the original readable source.
I'm glad to grant a reviewer temporary read access to the private repository so the unobfuscated source can be checked directly against the published build, or to walk through any specific function that triggered the detection.
My npm account has also been locked due to this automated flag. Could you please review the source and remove the malware advisory flag from my package? I am fully prepared to either republish the package unobfuscated, or declare it as dual-use content (contentPolicy + DISCLOSURE) if that helps avoid this in the future.
Thank you for your time and help.
(Edit: corrected an earlier inaccurate statement about the public repo containing unobfuscated source — it does not; the original source is private.)
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 2.5k
- Fork
- 772
- Merge trung bình
- 3 ngày 18 giờ
- Pull request đã merge (30 ngày)
- 48
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/advisory-database
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
github/advisory-database#9255 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/advisory-database#9164 · 1 reaction ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/advisory-database#8994 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
github/advisory-database#8898 · 4 bình luận · 1 reaction ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/advisory-database#8841 ·
Tất cả issue của github/advisory-database
Issue tương tự
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
canonical/paas-charm#368 · 1 bình luận ·
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
palladius/rails8-app-on-gcp#142 ·
-
addition to tracking list Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
StevenBlack/hosts#3256 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100