For the complete documentation index, see llms.txt. This page is also available as Markdown.

Reference D: Malicious package finding and issue fields

This reference lists the fields, descriptions, and resolution text for the malicious package finding and issue.

Finding attributes

Attribute
Value

XDM canonical finding type

Malicious package detected in code

Detection method

CAS_MALICIOUS_PACKAGE_SCANNER

Detection rule ID

BC_MAL_1

Default severity

Critical (always)

Finding and issue name

Malicious Package in <PackageName> version <PackageVersion>

Finding fields: Data source, Repository, Package Manager, Dependency Type, File Path, Branch, Backlog status, Collaborator, First Hash, First Commit Hash, Version detected, Malware ID, Vendor Link.

Issue classification: Issue Domain = POSTURE.

Issue table columns: Severity, Urgency, Malware ID, Name, Asset Name, Repository, AppSec Policy ID, Data Source, SLA, Branch, File Path, Status, Assignee, Created, Backlog Status.

Issue description: "The <DependencyType> package <PackageName>@<PackageVersion> was detected in package manager file <Path>[ on line <LineNumber>] and has been identified as a known malicious package (<MalwareID>)." When the advisory provides a summary, it is appended to the description.

Issue impact: The detected package version is associated with intentionally malicious behavior, such as credential theft, data exfiltration, or unauthorized remote access.

Last updated

Was this helpful?