> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/reference-d-malicious-package-finding-and-issue-fields.md).

# Reference D: Malicious package finding and issue fields

This reference lists the fields, descriptions, and resolution text for the malicious package finding and issue.

**Finding attributes**

| Attribute                  | Value                                                           |
| -------------------------- | --------------------------------------------------------------- |
| XDM canonical finding type | Malicious package detected in code                              |
| Detection method           | `CAS_MALICIOUS_PACKAGE_SCANNER`                                 |
| Detection rule ID          | `BC_MAL_1`                                                      |
| Default severity           | Critical (always)                                               |
| Finding and issue name     | Malicious Package in `<PackageName>` version `<PackageVersion>` |

**Finding fields:** Data source, Repository, Package Manager, Dependency Type, File Path, Branch, Backlog status, Collaborator, First Hash, First Commit Hash, Version detected, Malware ID, Vendor Link.

**Issue classification:** Issue Domain = POSTURE.

**Issue table columns:** Severity, Urgency, Malware ID, Name, Asset Name, Repository, AppSec Policy ID, Data Source, SLA, Branch, File Path, Status, Assignee, Created, Backlog Status.

**Issue description:** "The `<DependencyType>` package `<PackageName>@<PackageVersion>` was detected in package manager file `<Path>`\[ on line `<LineNumber>`] and has been identified as a known malicious package (`<MalwareID>`)." When the advisory provides a summary, it is appended to the description.

**Issue impact:** The detected package version is associated with intentionally malicious behavior, such as credential theft, data exfiltration, or unauthorized remote access.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/risk-and-remediation/malicious-packages/reference-d-malicious-package-finding-and-issue-fields.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
