Skip to content

added sl4x0.xyz malicious pacakges#1174

Merged
calebbrown merged 3 commits intoossf:mainfrom
KunalSin9h:sd-malpkg-mar-24
Apr 2, 2026
Merged

added sl4x0.xyz malicious pacakges#1174
calebbrown merged 3 commits intoossf:mainfrom
KunalSin9h:sd-malpkg-mar-24

Conversation

@KunalSin9h
Copy link
Copy Markdown
Contributor

@KunalSin9h KunalSin9h commented Mar 24, 2026

These are the packages, which are from same author *@sl4x0.xyz whose 60 other packages are already reported to OSV in 2025, its a new wave with dependency confusion probe.

Blog: https://safedep.io/sl4x0-dependency-confusion-campaign/

package which was reported in 2025, one of them was https://osv.dev/vulnerability/MAL-2025-48364, our analysis at that time.

@KunalSin9h
Copy link
Copy Markdown
Contributor Author

@calebbrown am i missing something?

@calebbrown
Copy link
Copy Markdown
Contributor

Sorry, all good! I got caught up dealing with the litellm, CanisterWorm and axios compromises.

@calebbrown calebbrown merged commit 8378731 into ossf:main Apr 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants