-= Per source details. Do not edit below this line.=-
The OpenSSF Package Analysis project identified 'proto-registry-metadata-api' @ 1.11.3.87.g981ef7d3d (rubygems) as malicious.
It is considered malicious because:
The OpenSSF Package Analysis project identified 'proto-registry-metadata-api' @ 1.11.3.87.g981ef7d3d (rubygems) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"sha256": "f1f7ab6f94cef6b0a1e53365370e91527c5c546ab409345d8a77877f5927f677",
"import_time": "2025-09-08T03:43:53.575331836Z",
"modified_time": "2025-09-01T09:50:38Z",
"source": "ossf-package-analysis",
"versions": [
"1.11.3.87.g981ef7d3d"
]
},
{
"import_time": "2026-07-18T10:46:29.345687859Z",
"sha256": "271564eec96a10712404ca068a5d3ebb0be5770bda7b1502f25d56225c220101",
"modified_time": "2026-07-18T01:58:02Z",
"versions": [
"1.11.3.87.g981ef7d3d"
],
"id": "GHSA-6xx3-55vw-qmp7",
"source": "ghsa-malware"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/proto-registry-metadata-api/MAL-2025-46920.json"