-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'google-apis-androidpublisher_v2' @ 0.0 (rubygems) as malicious.
It is considered malicious because: - The package communicates with a domain associated with malicious activity.
The OpenSSF Package Analysis project identified 'google-apis-androidpublisher_v2' @ 0.0 (rubygems) as malicious.
It is considered malicious because: - The package communicates with a domain associated with malicious activity.
{
"malicious-packages-origins": [
{
"import_time": "2023-08-10T06:16:36.932649705Z",
"modified_time": "2023-07-19T06:30:24.337173817Z",
"sha256": "715b9e91530380e15e848bc0374f342584cdd61853308582683eb214e0da9927",
"versions": [
"0.0"
],
"source": "ossf-package-analysis"
},
{
"import_time": "2026-07-18T10:46:30.573568907Z",
"source": "ghsa-malware",
"sha256": "56c5bd4f954aae8930b39053e2a4716c8c2a6184d4128d62457c6de371e403a4",
"versions": [
"0.0"
],
"id": "GHSA-hmfq-mrg8-79hh",
"modified_time": "2026-07-18T01:57:20Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/google-apis-androidpublisher_v2/MAL-2023-1426.json"