Reference D: Malicious package finding and issue fields
This reference lists the fields, descriptions, and resolution text for the malicious package finding and issue.
Finding attributes
XDM canonical finding type
Malicious package detected in code
Detection method
CAS_MALICIOUS_PACKAGE_SCANNER
Detection rule ID
BC_MAL_1
Default severity
Critical (always)
Finding and issue name
Malicious Package in <PackageName> version <PackageVersion>
Finding fields: Data source, Repository, Package Manager, Dependency Type, File Path, Branch, Backlog status, Collaborator, First Hash, First Commit Hash, Version detected, Malware ID, Vendor Link.
Issue classification: Issue Domain = POSTURE.
Issue table columns: Severity, Urgency, Malware ID, Name, Asset Name, Repository, AppSec Policy ID, Data Source, SLA, Branch, File Path, Status, Assignee, Created, Backlog Status.
Issue description: "The <DependencyType> package <PackageName>@<PackageVersion> was detected in package manager file <Path>[ on line <LineNumber>] and has been identified as a known malicious package (<MalwareID>)." When the advisory provides a summary, it is appended to the description.
Issue impact: The detected package version is associated with intentionally malicious behavior, such as credential theft, data exfiltration, or unauthorized remote access.
Last updated
Was this helpful?
