MAL-2025-6348

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/resource_registry/MAL-2025-6348.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2025-6348
Published
2025-07-30T05:46:30Z
Modified
2025-07-31T06:33:21Z
Summary
Malicious code in resource_registry (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Source: ossf-package-analysis (97ad7e4a2d8c7feaee7f61db0f1f57c90f92b4f92d6ca258fef4bc5f5107666d)

The OpenSSF Package Analysis project identified 'resource_registry' @ 1.0.22 (rubygems) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-07-30T06:09:53.622311471Z",
            "sha256": "1b140cb241610ea2331b27d7c8643d913747ced6af2dce96d3c0d807f5e3b352",
            "modified_time": "2025-07-30T05:46:30Z",
            "versions": [
                "0.0.1"
            ],
            "source": "ossf-package-analysis"
        },
        {
            "import_time": "2025-07-31T04:21:29.899088539Z",
            "sha256": "97ad7e4a2d8c7feaee7f61db0f1f57c90f92b4f92d6ca258fef4bc5f5107666d",
            "modified_time": "2025-07-31T04:13:51Z",
            "versions": [
                "1.0.22"
            ],
            "source": "ossf-package-analysis"
        }
    ]
}
References
Credits

Affected packages

RubyGems / resource_registry

Package

Name
resource_registry
Purl
pkg:gem/resource_registry

Affected ranges

Affected versions

0.*

0.0.1

1.*

1.0.22