False positive malware advisory for official [email protected] release
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 58/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- javascript
- 领域
- security
调研方向
首先,将 GitHub advisory GHSA-hpcx-pg6g-x697 与 osv/withdrawn/npm/astro/MAL-2026-10726.json 中已撤回的 OSV 记录以及关联的 OpenSSF PR #1383 进行比较。确认撤回证据,并追踪该 advisory 在此仓库中的表示方式;当误报 advisory 不再标记官方 [email protected] 发布版本时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
GitHub advisory GHSA-hpcx-pg6g-x697 incorrectly classifies [email protected] as malicious.
The advisory claims that:
- The legitimate Astro project is still on the v5.x release line
- [email protected] impersonates the real package
- obug, piccolore, and @astrojs/markdown-satteri are attacker-controlled typosquats
These claims are incorrect.
[email protected] is an official Astro release:
- Official release: https://github.com/withastro/astro/releases/tag/astro%407.1.0
- Official tag commit: fdd673cc193734d7818fe5ace39c86b9500b2754
- The release commit has GitHub’s verified signature
- The official package manifest declares version 7.1.0
- The official manifest includes obug, piccolore, and @astrojs/markdown-satteri
- The npm tarball integrity matches the official release
The dependencies are also legitimate:
- obug is maintained at https://github.com/sxzz/obug
- piccolore is maintained at https://github.com/delucis/piccolore
- @astrojs/markdown-satteri is maintained in the official Astro monorepo
- Astro’s v7 release notes explicitly document making Sätteri the default Markdown processor
Most importantly, the originating OpenSSF record has already been withdrawn as a false positive here.
The OpenSSF PR is titled “Remove false positive astro advisory.” The person who submitted the package on behalf of the Amazon researcher also commented:
Following @tolgaergin's rationale, I concur this was a false positive. Apologies for the inconvenience.
The withdrawn OSV record is here:
https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/astro/MAL-2026-10726.json
It contains:
"withdrawn": "2026-07-17T08:42:02Z"
It appears GitHub imported or published the advisory after the originating record had already been withdrawn. This is currently causing npm audit to report a critical malware finding for a legitimate Astro release.
- 主要语言
- 没有语言数据
- 星标
- 2.5k
- 派生
- 803
- 平均合并
- 7 天 3 小时
- 30 天内合并 PR
- 63
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/advisory-database 的其他 Issue
-
Update https://github.com/advisories/GHSA-5pf6-cq2v-23ww to include patched version可能已有人在做 @GreyforgeLabs 于 5 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 76/100
github/advisory-database#9879 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#9255 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#9164 · 1 个 reaction ·
维护者通常 1 天内回复
-
CVE-2026-5598 has incorrect fixed versions for bcprov-jdk packages可能已有人在做 @ECD5A 于 48 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
github/advisory-database#8994 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
github/advisory-database#8898 · 4 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
查看 github/advisory-database 的全部 Issue
相似的 Issue
-
config core enhancement
难度 1/5 1 小时以内 新手友好度 86/100
bunkerity/bunkerweb#4018 · 1 条评论 ·
维护者通常 1 天内回复
-
actor/human kind/bug priority/important-soon triage-accepted
难度 2/5 1-3 小时 新手友好度 66/100
kelos-dev/kelos#1804 · 2 条评论 ·
维护者通常 1 天内回复
-
security
难度 2/5 1-3 小时 新手友好度 82/100
Sendspin/sendspin-dotnet#339 ·
维护者通常 1 天内回复
-
The mantle IAM policy scopes ListModels and GetModel to a project ARN, which cannot authorise them未关闭
难度 2/5 1-3 小时 新手友好度 74/100
aws-samples/sample-per-model-bedrock#50 ·
维护者通常 1 天内回复
-
opencode: an unanswered --version probe launches opencode 2 without per-session service isolation未关闭
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复