Spectra Assure
Community
Docs
failIncident: Malware
Scanned: 6 days ago

d

Property descriptor factory
License: Permissive (ISC)
Published: almost 2 years ago




SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
No sensitive information found

Security

Vulnerabilities
No known vulnerabilities detected
Hardening
No application hardening issues

Threats

Tampering
No evidence of software tampering
Malware
1 protestware dependencies found

INCIDENTS FOR THIS VERSION:

malware
9 months agoReported By: ReversingLabs (Automated)
Learn more about malware detection

Popularity

2.19B
Recorded Downloads Since 2021
Contributor
Declared Dependencies
649
Dependents

Top issues

Problem

Authors of open source software may decide to use their projects to spread political messages. Running software packages that include protestware dependencies may trigger protest-related functions when executed in the targeted environments or geographies. Protest-motivated code is commonly implemented as a simple display of harmless messages that call for peace. However, over time protestware may evolve to include code that performs excessive logging, issues denial of service, or even deletes user files. Software packages that depend on protestware code are considered to be potentially unwanted applications. When political activism escalates to inclusion of destructive code, additional malware detection policies trigger to flag malicious intent.

Prevalence in npm community

0 packages
found in
Top 100
0 packages
found in
Top 1k
18 packages
found in
Top 10k
5465 packages
in community

Next steps

Inspect behaviors exhibited by the detected software components.
If the software behaviors differ from expected, investigate the build and release environment for software supply chain compromise.
Revise the use of components that raise these alarms. If you can't deprecate those components, make sure they are well-documented.
Avoid using this software package until it is vetted as safe.

Top behaviors

Prevalence in npm community

No behavior prevalence information at this time

Prevalence in npm community

Behavior often found in this community (Common)
0 packages
found in
Top 100
0 packages
found in
Top 1k
25 packages
found in
Top 10k
4626 packages
in community

Prevalence in npm community

No behavior prevalence information at this time

Prevalence in npm community

Behavior often found in this community (Common)
92 packages
found in
Top 100
716 packages
found in
Top 1k
7171 packages
found in
Top 10k
2147304 packages
in community

Top vulnerabilities

No vulnerabilities found.